Cisco Products Snort 3 Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in multiple Cisco products that use the Snort 3 Detection Engine. This vulnerability allows an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, disrupting packet inspection. The issue arises from incomplete parsing of SSL handshake ingress packets, which an attacker could exploit by sending crafted SSL handshake packets. When the Snort 3 Detection Engine restarts unexpectedly, it creates a denial-of-service condition.

Impact

Exploitation of this vulnerability causes the Snort 3 Detection Engine to restart unexpectedly, interrupting packet inspection and analysis.

Remediation

Cisco has released software updates that address this vulnerability. For Open Source Snort 3, users should upgrade to version 3.9.2.0 or later. For Cisco Secure Firewall Threat Defense Software, Snort 3 must be active, and users can check their version using the Cisco Software Checker tool. Cisco Meraki MX Security Appliances have been automatically updated with the Snort 3 package as of February 5, 2026.

Added: Mar 4, 2026, 9:03 PM
Updated: Mar 4, 2026, 9:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.0
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.