Junglewise Threat Intelligence

CVE-2026-20052: Cisco Secure Firewall Threat Defense Snort 3 memory management denial of service

CVE-2026-20052 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Technologies: Cisco Secure Firewall Threat Defense. Vendors: Cisco.

Executive brief

Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that inspects traffic, including encrypted connections. A memory management flaw in the Snort 3 detection engine can be triggered by specially crafted SSL packets, causing the inspection engine to unexpectedly restart and interrupt network traffic protection.

Technical details

This vulnerability is a memory management logic error (CWE-788) in the Snort 3 Detection Engine's SSL packet inspection functionality. An unauthenticated remote attacker can exploit it by sending crafted SSL packets through an established connection. The vulnerability requires Snort 3 to be enabled and an SSL decryption policy to be configured on the device. Successful exploitation causes a denial of service by forcing the Snort 3 Detection Engine to restart, temporarily disabling threat detection. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Secure Firewall Threat Defense

Timeline

  • 2026-03-04: disclosed

References

Related threats