SB2021081903 - Information disclosure in Multiple Cisco Products



SB2021081903 - Information disclosure in Multiple Cisco Products

Published: August 19, 2021

Security Bulletin ID SB2021081903
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2021-34749)

The vulnerability allows a remote attacker to exfiltrate data from a compromised host.

The vulnerability exists due to inadequate filtering of the SSL handshake in Server Name Identification (SNI) request filtering. A remote attacker can use data from the SSL client hello packet to communicate with an external server and gain access to sensitive information on the target system.


Remediation

Install update from vendor's website.