Executive brief
Snort 3 is a network intrusion detection and prevention engine used in Cisco firewalls and routers to monitor traffic for malicious activity. A vulnerability in the VBA file decompression feature allows remote attackers to send crafted files that crash the detection engine, disabling security monitoring and creating a denial of service condition.
Technical details
The vulnerability exists in Snort 3's Visual Basic for Applications (VBA) decompression engine due to improper range checking when decompressing user-controlled VBA data. An unauthenticated, remote attacker can send crafted VBA data to trigger a heap buffer overflow, causing the Snort 3 Detection Engine to unexpectedly restart and resulting in a denial of service condition. The vulnerability affects multiple Cisco products running Snort 3, including Secure Firewall Threat Defense (FTD), IOS XE devices with Unified Threat Defense (UTD) enabled, and open-source Snort 3. VBA decompression is not enabled by default in FTD, but affects IMAP, SMTP, HTTP, and POP3 inspection engines when configured. Cisco has released software updates; workarounds are available.
Affected products
- Cisco Snort 3 Open source releases (specific versions in advisory)
- Cisco Secure Firewall Threat Defense 7.2.0 and later with Snort 3 enabled
- Cisco IOS XE releases with Unified Threat Defense (UTD) Snort IPS Engine
- Cisco Catalyst 8000V Edge Software vulnerable releases with UTD enabled
- Cisco Catalyst 8200 Series Edge Platforms vulnerable releases with UTD enabled
- Cisco Catalyst 8300 Series Edge Platforms vulnerable releases with UTD enabled
- Cisco Catalyst 8500L Edge Platforms vulnerable releases with UTD enabled
Timeline
- 2026-03-04: advisory: Cisco security advisory published (cisco-sa-ftd-snort3-vbavuls-96UcVVed)