Remote Code Execution Vulnerability in Cisco Snort 3 VBA Feature
CVE-2026-20053
5.8MEDIUM
What is CVE-2026-20053?
Cisco Snort 3 is impacted by a vulnerability related to its VBA feature, enabling unauthenticated remote attackers to disrupt the detection engine. This flaw arises from improper range checks during the decompression of user-controlled VBA data. By sending specially crafted data to the Snort 3 Detection Engine, an attacker may exploit this vulnerability, resulting in an overflow of heap data and potentially leading to a denial of service condition.
Affected Version(s)
Cisco Cyber Vision 3.0.0
Cisco Cyber Vision 3.0.2
Cisco Cyber Vision 3.0.3