Cisco Products Snort 3 Visual Basic for Applications Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in multiple Cisco products that utilize Snort 3, specifically within the Visual Basic for Applications (VBA) feature. This vulnerability allows an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash, leading to an unexpected restart and a denial-of-service condition. The issue arises from improper error checking when decompressing VBA data, which can be exploited by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device.

Impact

Exploitation of this vulnerability causes the Snort 3 Detection Engine to crash, leading to a denial-of-service condition.

Remediation

Cisco has released software updates to address this vulnerability. For Cisco Secure Firewall Threat Defense (FTD) Software, the vulnerability can be mitigated by disabling VBA decompression, which is not enabled by default. Instructions for managing Snort 3 configurations are available in the Cisco Secure Firewall Management Center Snort 3 Configuration Guide, Version 7.2.

Added: Mar 4, 2026, 6:44 PM
Updated: Mar 4, 2026, 6:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.