Executive brief
Snort 3 is a network intrusion detection and prevention engine deployed across multiple Cisco security products including firewalls, threat defense systems, and routers. A flaw in SSL handshake packet parsing allows unauthenticated remote attackers to send specially crafted packets that crash the detection engine, temporarily disrupting packet inspection and creating a window for malicious traffic to bypass security monitoring.
Technical details
This vulnerability stems from incomplete parsing of SSL handshake ingress packets in the Snort 3 Detection Engine (CWE-248, CWE-392, CWE-400, CWE-667, CWE-787). An unauthenticated remote attacker can exploit this via network-level access by sending crafted SSL/TLS handshake packets. When processed by the vulnerable engine, these packets trigger an unexpected restart of Snort 3, causing a temporary denial of service and interruption of packet inspection capabilities. No authentication or user interaction is required. Cisco has released software updates addressing these vulnerabilities; no workarounds are available.
Affected products
- Cisco Snort 3 Multiple versions; see fixed software section
- Cisco Secure Firewall Threat Defense Multiple releases with Snort 3 configured
- Cisco IOS XE Software Multiple releases with UTD Snort IPS Engine enabled
- Cisco Meraki MX Series Multiple MX models running vulnerable Meraki Software
- Cisco Cyber Vision Multiple releases
Timeline
- 2026-03-04: disclosed: CVE-2026-20005 published; multiple related CVEs (CVE-2026-20065, CVE-2026-20066, CVE-2026-20067, CVE-2026-20068) also disclosed