MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2026-20058

CVSS 5.8v3.1pub. 2026-03-04upd. 2026-08-20

Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart, causing a DoS condition.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
  • Cisco Secure Firewall Threat Defense

    APP
    Cisco
    7.2.07.2.0.17.2.17.2.107.2.10.27.2.27.2.37.2.47.2.4.17.2.57.2.5.17.2.5.27.2.67.2.77.2.8+ 22 more
  • Cisco Snort

    APP
    Cisco
    3.0.0-233 – 3.9.6.0 (excl.)
  • Cisco Unified Threat Defense Snort Intrusion Prevention System Engine

    OS
    Cisco
    17.12.1a17.12.217.12.317.12.3a17.12.417.12.4a17.12.4b17.12.517.12.5a17.12.5b17.12.5c17.12.5d17.12.617.13.1a17.14.1a+ 15 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-20333CRITICAL9.9⚠ KEVPL ✓same product

RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2024-20412CRITICAL9.3PL ✓same product

Cisco FTD: statyczne konta z zakodowanymi hasłami umożliwiają nieautoryzowany dostęp

CVE-2020-3187CRITICAL9.1PL ✓same product

Path Traversal w Cisco ASA i FTD — nieautoryzowany dostęp do plików przez WebVPN/AnyConnect

CVE-2018-0101CRITICAL10.0PL ✓same product

Cisco ASA SSL VPN — double free umożliwiający RCE lub DoS