CVE-2025-20360
published 2025-10-15CVE-2025-20360: Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3…
PriorityP335medium5.8CVSS 3.1
AVNACLPRNUINSCCNINAL
EPSS
0.36%
27.9th percentile
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.
This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are parsed. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition when the Snort 3 Detection Engine unexpectedly restarts.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
vendor_cisco·2025-10-15·CVSS 6.5
CVE-2025-20359 [MEDIUM] CWE-127 Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak possible sensitive information or to restart.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-mime-vulns-tTL8PgVH
Cisco
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20360 Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
CVE-2025-20360: Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak possible sensitive information or to restart. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-127, CWE-805, CWE-127, CWE-805
Bug IDs: CSCwo71401, CSCwq03467, CSCwq15864, CSCwo71401, CSCwq03467
GHSA
GHSA-6w3w-cx38-4j8c: Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the
ghsa_unreviewed·2025-10-15
CVE-2025-20360 [MEDIUM] CWE-805 GHSA-6w3w-cx38-4j8c: Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.
This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are parsed. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition when the Snort 3 Detection Engine unexpectedly restarts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-15
Published