Executive brief
Snort 3 is a network intrusion detection and prevention engine deployed across multiple Cisco security products including firewalls, routers, and edge platforms. An unauthenticated remote attacker can send specially crafted packets to crash the Snort 3 engine, interrupting packet inspection and creating a window for malicious traffic to bypass security controls. This results in loss of visibility and protection for network traffic.
Technical details
The vulnerability exists in the binder module initialization logic of the Snort 3 Detection Engine, classified as an error-handling issue (CWE-248, CWE-392). An unauthenticated, network-adjacent attacker can exploit this by sending certain packets through an established connection parsed by Snort 3, triggering an unhandled exception that causes the detection engine to restart unexpectedly. The attack requires no authentication or user interaction and is triggered on receipt of malicious packets. A successful exploit results in a denial-of-service condition interrupting packet inspection. Patches are available; no workarounds exist.
Affected products
- Cisco Snort 3 Multiple vulnerable releases
- Cisco Secure Firewall Threat Defense Multiple releases with Snort 3 configured
- Cisco IOS XE Multiple releases with UTD Snort IPS Engine enabled
- Cisco Catalyst 8000V Edge Software Multiple vulnerable releases
- Cisco Catalyst 8200 Series Edge Platforms Multiple vulnerable releases
- Cisco Cloud Services Router 1000V Multiple vulnerable releases
- Cisco Cyber Vision Multiple vulnerable releases
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published