Executive brief
Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that uses Snort intrusion detection to block malicious traffic. A logic error in how Snort rules are evaluated allows attackers to craft packets that bypass configured security rules and gain unauthorized access to protected networks. This effectively disables critical security controls protecting corporate infrastructure.
Technical details
The vulnerability is a logic error (CWE-284: Improper Access Control) in the integration of Snort 2 and Snort 3 deep packet inspection engines with Cisco Secure FTD. When inspecting packets with nested or layered connections (inner and outer packets), different Snort rules may be applied inconsistently, allowing traffic to bypass configured rules. An unauthenticated remote attacker can send specially crafted packets to a targeted FTD device with an active intrusion policy and Snort enabled to exploit this flaw. Successful exploitation allows denied traffic to pass through to the protected network. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Threat Defense See Cisco Software Checker for affected versions
Timeline
- 2026-03-04: disclosed