Executive brief
Multiple Cisco network security products including Secure Firewall, Threat Defense, and IOS XE routers contain a vulnerability in their Snort 3 intrusion detection engine. An attacker can remotely send specially crafted data to crash the Snort detection engine, causing temporary service outages and leaving networks unprotected from intrusions during the restart period.
Technical details
This vulnerability exists in the Snort 3 Visual Basic for Applications (VBA) decompression engine and stems from insufficient error checking when processing VBA data. The vulnerability affects multiple CWE classes including CWE-122 (heap-based buffer overflow), CWE-369 (divide by zero), CWE-786 (access of memory location before start of buffer), and CWE-835 (infinite loop). An unauthenticated remote attacker can exploit this by sending a malformed VBA packet to a device running Snort 3 with VBA macro decompression enabled (supported on IMAP, SMTP, HTTP, and POP3 inspectors). A successful exploit causes the Snort 3 Detection Engine to unexpectedly restart, resulting in denial of service. Cisco has released software updates addressing these vulnerabilities, and workarounds are available.
Affected products
- Cisco Snort 3 vulnerable versions documented in fixed software section
- Cisco Secure Firewall Threat Defense 7.2.0 and later with VBA decompression enabled
- Cisco IOS XE with Unified Threat Defense Snort IPS Engine or UTD Engine for SD-WAN
- Cisco Secure Firewall Management Center 7.2.0 and later
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published