Buffer Handling Vulnerability in Snort 3 by Cisco
CVE-2025-20359
6.5MEDIUM
What is CVE-2025-20359?
A vulnerability exists in the Snort 3 HTTP Decoder used by Cisco's Snort 3 product, allowing potential exposure of sensitive data or system disruption. This issue arises from improper buffer handling during the parsing of MIME fields within HTTP headers. Attackers can exploit this by sending specially crafted HTTP packets to the Snort 3 Detection Engine, leading to either unexpected system crashes or unauthorized disclosure of sensitive data. The under-read condition puts extra data at risk, as it may expose information that should remain secure. Immediate action is recommended to evaluate and secure affected systems.
Affected Version(s)
Cisco Cyber Vision 3.0.0
Cisco Cyber Vision 3.0.2
Cisco Cyber Vision 3.0.3