DCE/RPC Processing Vulnerability in Cisco Snort 3
CVE-2026-20027
5.3MEDIUM
What is CVE-2026-20027?
A vulnerability exists in Cisco Snort 3 due to improper buffer handling in the processing of DCE/RPC requests. This flaw can allow unauthenticated attackers to trigger out-of-bounds read conditions by sending excessive DCE/RPC requests over established connections monitored by Snort 3. As a result, sensitive information could be disclosed or the Snort 3 Detection Engine could be prompted to restart, disrupting packet inspection functions and leading to potential data exposure.
Affected Version(s)
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1