Cisco Snort vulnerabilities

3 known vulnerabilities affecting cisco/snort.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-20342HIGHCVSS 8.6≥ 3.0.0.0, < 3.1.74.02024-10-23
CVE-2024-20342 [MEDIUM] CWE-1025 CVE-2024-20342: Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort d Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic
nvd
CVE-2024-20363MEDIUMCVSS 5.8≥ 3.0.0-233, < 3.1.69.02024-05-22
CVE-2024-20363 [MEDIUM] CWE-290 CVE-2024-20363: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IP Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP
nvd
CVE-2021-40116HIGHCVSS 7.5≥ 3.0.0.0, < 3.1.0.1002021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd