Format Destruction Detection Bypass
CSCws92019Cisco would like to thank Christopher Aziz of Bombadil Systems for reporting this issue.
Summary
Cisco opened this bug to evaluate detection improvements after I reported that format destruction techniques—novel encoding and chunking methods—can bypass in-transit malware detection by Cisco Secure Endpoint Connectors. The issue affects devices running default configurations, and no workaround is available.
Cisco's PSIRT evaluated the issue and determined it does not meet their criteria for PSIRT ownership. Instead, it is being addressed through normal resolution channels as a product improvement rather than a security vulnerability.
Affected Products
- Cisco Secure Endpoint
- Cisco Secure Endpoint Private Cloud
Details
| Field | Value |
|---|---|
| Bug ID | CSCws92019 |
| Severity | 3 - Moderate |
| Status | Open |
| Created | January 21, 2026 |
| Last Modified | February 24, 2026 |
| Workaround | None |
The original Cisco bug entry (CSCws92019) requires a Cisco account to access. This page summarizes the acknowledgment for reference. All quoted text is attributed to Cisco Systems, Inc.
Related
The Detection Gap — Full technical writeup on format destruction techniques.
Veriduct Prime — Open source format destruction framework.
Cisco Bug Search — Original vendor entry (requires Cisco account).