Denial of Service Vulnerability in Snort 3 by Cisco
CVE-2026-20057
5.8MEDIUM
What is CVE-2026-20057?
Cisco's Snort 3 is susceptible to a vulnerability in its Visual Basic for Applications (VBA) feature, allowing remote unauthenticated attackers to potentially crash the Snort 3 Detection Engine. This vulnerability arises due to inadequate error handling during the decompression of VBA data. An attacker can exploit this weakness by sending maliciously crafted VBA data, leading to unexpected restarts of the Snort 3 Detection Engine and creating a denial of service (DoS) condition on affected devices.
Affected Version(s)
Cisco Cyber Vision 3.0.0
Cisco Cyber Vision 3.0.2
Cisco Cyber Vision 3.0.3