Executive brief
Cisco products using Snort 3 detection engine contain a flaw in HTTP JavaScript normalization that allows remote attackers to crash the inspection engine. When Snort 3 restarts unexpectedly, packet inspection is interrupted, potentially leaving network traffic uninspected and exposing the protected network. This could disrupt security monitoring and allow malicious traffic to pass undetected during outages.
Technical details
The vulnerability exists in the JSTokenizer normalization logic when Snort 3 performs HTTP inspection of JavaScript content. An unauthenticated, remote attacker can send crafted HTTP packets through an established connection that triggers an error in this normalization logic, causing the Snort 3 Detection Engine to restart unexpectedly and resulting in a denial of service condition. The attack requires the JSTokenizer feature to be active (it is not enabled by default). The vulnerable component is part of Snort 3, which is included in Cisco Secure Firewall Threat Defense (FTD), IOS XE with Unified Threat Defense (UTD), and other Cisco security products. Cisco has released software updates addressing this vulnerability.
Affected products
- Cisco Open Source Snort 3
- Cisco Secure Firewall Threat Defense
- Cisco IOS XE
- Cisco Catalyst 8000V Edge Software
- Cisco Catalyst 8200 Series Edge Platforms
- Cisco Catalyst 8300 Series Edge Platforms
- Cisco Catalyst 8500L Edge Platforms
- Cisco Cloud Services Routers 1000V
- Cisco Cyber Vision
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published