Memory Management Vulnerability in Cisco Secure Firewall Snort 3 Detection Engine
CVE-2026-20052
5.8MEDIUM
What is CVE-2026-20052?
A logic error in the memory management during SSL packet inspection within the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense Software enables unauthenticated, remote attackers to exploit the system. By sending crafted SSL packets through an active connection, attackers may trigger a restart of the Snort 3 Detection Engine, leading to a denial of service (DoS) condition.
Affected Version(s)
Cisco Secure Firewall Threat Defense (FTD) Software 7.4.0
Cisco Secure Firewall Threat Defense (FTD) Software 7.4.1
Cisco Secure Firewall Threat Defense (FTD) Software 7.4.1.1