Cisco Products Snort 3 HTTP MIME Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in multiple Cisco products that use Snort 3 as their HTTP decoder. This vulnerability allows an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, leading to a temporary disruption of service. The issue arises from insufficient error checking when parsing the MIME fields of HTTP headers. An attacker could exploit this by sending crafted HTTP packets through an established connection, causing the Snort 3 Detection Engine to restart unexpectedly.

Impact

Exploitation of this vulnerability causes the Snort 3 Detection Engine to restart unexpectedly, creating a denial-of-service condition.

Remediation

Cisco has released software updates to address this vulnerability. For information about fixed releases, consult the Cisco Security Advisory or use the Cisco Software Checker tool. Cisco Meraki plans to release fixes in February 2026.

Added: Oct 15, 2025, 5:26 PM
Updated: Oct 15, 2025, 5:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.