Information disclosure in Sourcefire products - CVE-2021-34749
Published: August 19, 2021
Vulnerability details
The vulnerability allows a remote attacker to exfiltrate data from a compromised host.
The vulnerability exists due to inadequate filtering of the SSL handshake in Server Name Identification (SNI) request filtering. A remote attacker can use data from the SSL client hello packet to communicate with an external server and gain access to sensitive information on the target system.
Affected software
Cisco Web Security Appliance
3000 Series Industrial Security Appliance (ISA)
Snort