CVE-2026-20068
published 2026-03-04CVE-2026-20068: Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort…
PriorityP335medium5.8CVSS 3.1
AVNACLPRNUINSCCNINAL
EPSS
0.43%
35.0th percentile
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete error checking when parsing remote procedure call (RPC) data. An attacker could exploit this vulnerability by sending crafted RPC packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition when the Snort 3 Detection Engine unexpectedly restarts.
Affected
154 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6m9q-hwqp-8rv6: Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause
ghsa_unreviewed·2026-03-04
CVE-2026-20068 [MEDIUM] CWE-248 GHSA-6m9q-hwqp-8rv6: Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete error checking when parsing remote procedure call (RPC) data. An attacker could exploit this vulnerability by sending crafted RPC packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition when the Snort 3 Detection Engine unexpectedly restarts.
Cisco
Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
vendor_cisco·2026-03-04·CVSS 5.8
CVE-2026-20005 [MEDIUM] CWE-248 Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-multi-dos-XFWkWSwz
This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure
Cisco
Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20068 Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
CVE-2026-20068: Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-248, CWE-392, CWE-400, CWE-248, CWE-392, CWE-400, CWE-667, CWE-787, CWE-248, CWE-392, CWE-400, CWE-248, CWE-392, CWE-400, CWE-667, CWE-787
Bug IDs: CSCwn49805, CSCwn65473, CSCwo93207, CSCwn49805, CSCwn65473
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-04
Published