Executive brief
Cisco's Snort 3 detection engine, used in firewalls and security appliances to inspect network traffic, contains a vulnerability that allows remote attackers to crash the engine by sending specially crafted network packets. When the engine restarts unexpectedly, the firewall stops inspecting traffic, leaving the network unprotected until the service recovers.
Technical details
The vulnerability exists in the Snort 3 detection engine's HTTP header parsing logic, specifically in the handling of Multicast DNS fields (CWE-248: Unchecked Error Condition). An unauthenticated remote attacker can exploit this by sending malformed HTTP packets over an established connection. The incomplete error checking fails to validate the DNS fields before processing, causing an unexpected restart of the detection engine and interrupting packet inspection. The attack requires network access but no authentication or user interaction. Patches are available from Cisco for affected software releases.
Affected products
- Cisco Snort 3 Multiple versions
- Cisco Secure Firewall Threat Defense (FTD) Multiple versions with Snort 3 configured
- Cisco IOS XE Software Multiple versions with UTD Snort IPS Engine
- Cisco Catalyst 8000V Edge Software Multiple versions with UTD
- Cisco Catalyst 8200 Series Edge Platforms Multiple versions with UTD
- Cisco Catalyst 8300 Series Edge Platforms Multiple versions with UTD
- Cisco Catalyst 8500L Edge Platforms Multiple versions with UTD
- Cisco Cloud Services Router 1000V Multiple versions with UTD
- Cisco Cyber Vision Multiple versions
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published