Executive brief
Cisco Secure Firewall Threat Defense (FTD) Software contains a flaw in how the Snort 2 detection engine processes SSL/TLS certificates. An attacker on the network can send a specially crafted SSL connection request that crashes the detection engine, temporarily disabling threat detection and network monitoring until the system restarts. This results in a denial-of-service condition that degrades network security oversight.
Technical details
The vulnerability is an incomplete validation flaw (CWE-805) in the Snort 2 Detection Engine's SSL/TLS certificate parsing logic. An unauthenticated, remote attacker can exploit this by sending a crafted SSL connection setup request that triggers improper handling in the certificate validation code. The attack requires only network reachability and no authentication; the malformed SSL certificate causes the Snort 2 process to crash and restart, resulting in a denial of service. Cisco has released software updates; no workarounds are available. Open Source Snort 2 has reached end of life and will not receive patches.
Affected products
- Cisco Secure Firewall Threat Defense Multiple releases with Snort 2 configured (default on upgrades from 6.7.0 or earlier to 7.0.0+; deprecated in 7.7.0+)
- Open Source Snort Snort 2 All versions; final release 2.9.20 (end of life)
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published