HTTP Header Parsing Vulnerability in Cisco Snort 3 Detection Engine
CVE-2025-20360
5.8MEDIUM
What is CVE-2025-20360?
Cisco's Snort 3 Detection Engine is affected by a vulnerability in its HTTP Decoder, which allows unauthenticated remote attackers to exploit a flaw in the processing of MIME fields in HTTP headers. This weakness stems from incomplete error checking during the parsing process. By sending specially crafted HTTP packets over an established connection, an attacker can induce a denial-of-service condition, prompting the Snort 3 Detection Engine to unexpectedly restart. Organizations using this product should prioritize mitigations to safeguard against potential exploitation.
Affected Version(s)
Cisco Cyber Vision 3.0.4
Cisco Cyber Vision 3.0.0
Cisco Cyber Vision 3.0.1