Executive brief
Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that inspects traffic, including encrypted connections. A memory management flaw in the Snort 3 detection engine can be triggered by specially crafted SSL packets, causing the inspection engine to unexpectedly restart and interrupt network traffic protection.
Technical details
This vulnerability is a memory management logic error (CWE-788) in the Snort 3 Detection Engine's SSL packet inspection functionality. An unauthenticated remote attacker can exploit it by sending crafted SSL packets through an established connection. The vulnerability requires Snort 3 to be enabled and an SSL decryption policy to be configured on the device. Successful exploitation causes a denial of service by forcing the Snort 3 Detection Engine to restart, temporarily disabling threat detection. Cisco has released software updates to address this issue; no workarounds are available.
Affected products
- Cisco Secure Firewall Threat Defense
Timeline
- 2026-03-04: disclosed