Cisco Snort vulnerabilities
12 known vulnerabilities affecting cisco/snort.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2024-20342P3HIGHCVSS 8.6≥ 3.0.0.0, < 3.1.74.02024-10-23
CVE-2024-20342 [HIGH] CWE-1025 CVE-2024-20342: Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort d
Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter.
This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic th
nvd
CVE-2021-40116P3HIGHCVSS 7.5≥ 3.0.0.0, < 3.1.0.1002021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent
Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd
CVE-2026-20067P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.5.02026-03-04
CVE-2026-20067 [MEDIUM] CWE-787 CVE-2026-20067: Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete error checking when parsing the Multicast DNS fields of the HTTP hea
nvd
CVE-2026-20066P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.7.02026-03-04
CVE-2026-20066 [MEDIUM] CWE-400 CVE-2026-20066: Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to an error in the JSTokenizer normalization logic when the HTTP inspection normal
nvd
CVE-2026-20005P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.2.02026-03-04
CVE-2026-20005 [MEDIUM] CWE-392 CVE-2026-20005: Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete parsing of the SSL handshake ingress packets. An attacker could explo
nvd
CVE-2026-20054P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.3.02026-03-04
CVE-2026-20054 [MEDIUM] CWE-835 CVE-2026-20054: Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort
nvd
CVE-2026-20053P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.3.02026-03-04
CVE-2026-20053 [MEDIUM] CWE-122 CVE-2026-20053: Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit this vulnerability by sending cra
nvd
CVE-2026-20068P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.2.02026-03-04
CVE-2026-20068 [MEDIUM] CWE-248 CVE-2026-20068: Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to incomplete error checking when parsing remote procedure call (RPC) data. An att
nvd
CVE-2026-20058P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.6.02026-03-04
CVE-2026-20058 [MEDIUM] CWE-786 CVE-2026-20058: Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow
Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities by sending crafted VBA data to th
nvd
CVE-2026-20065P3MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.6.3.02026-03-04
CVE-2026-20065 [MEDIUM] CWE-667 CVE-2026-20065: Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could a
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.
This vulnerability is due to an error in the binder module initialization logic of the Snort Detection Engin
nvd
CVE-2026-20057P4MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.9.3.02026-03-04
CVE-2026-20057 [MEDIUM] CWE-369 CVE-2026-20057: Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability
nvd
CVE-2024-20363P4MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.1.69.02024-05-22
CVE-2024-20363 [MEDIUM] CWE-290 CVE-2024-20363: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IP
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP
nvd