#VU55978 Information disclosure in Sourcefire products - CVE-2021-34749
Published: August 19, 2021
3000 Series Industrial Security Appliance (ISA)
Cisco Web Security Appliance
Snort
Cisco Firewall Threat Defense (FTD)
Cisco Systems, Inc
Sourcefire
Description
The vulnerability allows a remote attacker to exfiltrate data from a compromised host.
The vulnerability exists due to inadequate filtering of the SSL handshake in Server Name Identification (SNI) request filtering. A remote attacker can use data from the SSL client hello packet to communicate with an external server and gain access to sensitive information on the target system.