Network Detection Bypass in Suricata by Open Information Security Foundation
CVE-2025-59147
7.5HIGH
What is CVE-2025-59147?
A vulnerability in Suricata, a network IDS and IPS engine, allows attackers to bypass detection by sending crafted traffic with multiple SYN packets featuring different sequence numbers within the same flow tuple. This manipulation can cause Suricata to fail in identifying the TCP session correctly. In IDS mode, this results in a logging bypass, while in IPS mode, it prevents the appropriate flow from being blocked. Users are advised to update to versions 7.0.12 or 8.0.1 to mitigate this issue.
Affected Version(s)
suricata < 7.0.12 < 7.0.12
suricata >= 8.0.0, < 8.0.1 < 8.0.0, 8.0.1