Cisco Products Snort 3 DCE/RPC Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in multiple Cisco products running Snort 3, specifically in the processing of DCE/RPC requests. This issue could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, disrupting packet inspection. The vulnerability arises from improper buffer handling when processing DCE/RPC requests, leading to a buffer out-of-bounds read. Exploitation involves sending a high volume of DCE/RPC requests through an established connection that Snort 3 is inspecting, potentially allowing the attacker to access sensitive information within the Snort 3 data stream.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information being processed by the Snort 3 Detection Engine.

Remediation

Cisco has released software updates to address this vulnerability. For Open Source Snort 3, users should upgrade to version 3.9.6.0. For Cisco Secure Firewall Threat Defense Software, hot fixes are available for versions 7.0 and 7.2. Cisco Meraki plans to release fixes in February 2026.

Added: Jan 7, 2026, 5:31 PM
Updated: Jan 7, 2026, 5:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
1.9
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.