Junglewise Threat Intelligence

CVE-2026-20005: Cisco Snort 3 Detection Engine denial of service in SSL handshake parsing

CVE-2026-20005 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Technologies: Cisco Cyber Vision, Cisco Snort 3, Cisco Secure Firewall Threat Defense, Cisco IOS XE Software. Vendors: Cisco.

Executive brief

Snort 3 is a network intrusion detection and prevention engine deployed across multiple Cisco security products including firewalls, threat defense systems, and routers. A flaw in SSL handshake packet parsing allows unauthenticated remote attackers to send specially crafted packets that crash the detection engine, temporarily disrupting packet inspection and creating a window for malicious traffic to bypass security monitoring.

Technical details

This vulnerability stems from incomplete parsing of SSL handshake ingress packets in the Snort 3 Detection Engine (CWE-248, CWE-392, CWE-400, CWE-667, CWE-787). An unauthenticated remote attacker can exploit this via network-level access by sending crafted SSL/TLS handshake packets. When processed by the vulnerable engine, these packets trigger an unexpected restart of Snort 3, causing a temporary denial of service and interruption of packet inspection capabilities. No authentication or user interaction is required. Cisco has released software updates addressing these vulnerabilities; no workarounds are available.

Affected products

  • Cisco Snort 3 Multiple versions; see fixed software section
  • Cisco Secure Firewall Threat Defense Multiple releases with Snort 3 configured
  • Cisco IOS XE Software Multiple releases with UTD Snort IPS Engine enabled
  • Cisco Meraki MX Series Multiple MX models running vulnerable Meraki Software
  • Cisco Cyber Vision Multiple releases

Timeline

  • 2026-03-04: disclosed: CVE-2026-20005 published; multiple related CVEs (CVE-2026-20065, CVE-2026-20066, CVE-2026-20067, CVE-2026-20068) also disclosed

References

Related threats