Denial of Service Vulnerability in Cisco Snort 3 Detection Engine
CVE-2026-20058
5.8MEDIUM
What is CVE-2026-20058?
The Cisco Snort 3 Detection Engine is susceptible to vulnerabilities stemming from improper error checking during the decompression of VBA data. An unauthenticated, remote attacker can exploit this flaw by sending specially crafted VBA data to the Snort 3 Detection Engine. A successful attack may result in unexpected restarts of the engine, leading to a Denial of Service condition, impacting the availability of services reliant on the affected device.
Affected Version(s)
Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0
Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0.1
Cisco Secure Firewall Threat Defense (FTD) Software 7.2.1