Junglewise Threat Intelligence

CVE-2025-20359: Cisco Snort 3 buffer under-read in HTTP MIME decoder

CVE-2025-20359 · Severity: medium · CVSS 6.5 · Published 2025-10-15

Technologies: Cisco Cyber Vision, Cisco Snort 3, Cisco Secure Firewall Threat Defense, Cisco Catalyst 8000V Edge Software, Cisco Catalyst 8500L Edge Platforms, Cisco Cloud Services Router 1000V, Cisco IOS XE, Cisco Catalyst 8300 Series Edge Platforms, Cisco Catalyst 8200 Series Edge Platforms. Vendors: Cisco.

Executive brief

Cisco Snort 3, a network intrusion detection engine used across multiple Cisco security products, contains a flaw in how it processes HTTP email-style headers (MIME fields). An attacker can send specially crafted network packets to trigger either a crash of the detection engine (denying its protective functions) or leak sensitive data from memory. This affects firewalls, routers, and security appliances that rely on Snort 3.

Technical details

The vulnerability is a buffer under-read (CWE-127, CWE-805) in the Snort 3 HTTP MIME field parser logic. When processing MIME headers in HTTP traffic, improper buffer handling causes the decoder to read from invalid memory locations, resulting in either a crash (denial of service) or information disclosure of sensitive data in the network stream. An unauthenticated remote attacker can exploit this by sending crafted HTTP packets through an established connection monitored by Snort 3, with no authentication or special preconditions required. Cisco has released software updates to address the vulnerability; no workarounds are available.

Affected products

  • Cisco Snort 3 Multiple versions (see vendor advisory for specific ranges)
  • Cisco Secure Firewall Threat Defense 7.0.0 and later (when Snort 3 is configured)
  • Cisco IOS XE Releases with vulnerable Unified Threat Defense (UTD) Snort IPS Engine
  • Cisco Catalyst 8000V Edge Software Releases with vulnerable UTD
  • Cisco Catalyst 8200 Series Edge Platforms Releases with vulnerable UTD
  • Cisco Catalyst 8300 Series Edge Platforms Releases with vulnerable UTD
  • Cisco Catalyst 8500L Edge Platforms Releases with vulnerable UTD
  • Cisco Cloud Services Router 1000V Releases with vulnerable UTD
  • Cisco Integrated Services Virtual Router Releases with vulnerable UTD
  • Cisco Meraki MX Series Multiple MX models with vulnerable Meraki software releases
  • Cisco Cyber Vision Vulnerable releases

Timeline

  • 2025-10-15: disclosed: Cisco Security Advisory published

References

Related threats