HTTP Header Parsing Vulnerability in Cisco Snort 3 Detection Engine
CVE-2025-20360

5.8MEDIUM

What is CVE-2025-20360?

Cisco's Snort 3 Detection Engine is affected by a vulnerability in its HTTP Decoder, which allows unauthenticated remote attackers to exploit a flaw in the processing of MIME fields in HTTP headers. This weakness stems from incomplete error checking during the parsing process. By sending specially crafted HTTP packets over an established connection, an attacker can induce a denial-of-service condition, prompting the Snort 3 Detection Engine to unexpectedly restart. Organizations using this product should prioritize mitigations to safeguard against potential exploitation.

Affected Version(s)

Cisco Cyber Vision 3.0.4

Cisco Cyber Vision 3.0.0

Cisco Cyber Vision 3.0.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20360 : HTTP Header Parsing Vulnerability in Cisco Snort 3 Detection Engine