CVE-2026-20026: Multiple Cisco Products Snort 3 DCERPC Vulnerabilities
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in buffer handling logic when processing DCE/RPC requests, which can result in a buffer use-after-free read. An attacker could exploit this vulnerability by sending a large number of DCE/RPC requests through an established connection that is inspected by Snort 3. A successful exploit could allow the attacker to unexpectedly restart the Snort 3 Detection Engine, which could cause a denial of service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20026?
CVE-2026-20026 has a medium severity rating as it allows an unauthenticated remote attacker to potentially disrupt services or leak sensitive information.
How do I fix CVE-2026-20026?
To fix CVE-2026-20026, it is recommended to apply the latest patches or updates provided by Cisco for the Snort 3 Detection Engine.
What are the risks associated with CVE-2026-20026?
The risks associated with CVE-2026-20026 include potential exposure of sensitive information and interruption of packet inspection services.
Which products are affected by CVE-2026-20026?
CVE-2026-20026 affects the Cisco Snort 3 Detection Engine specifically.
Can CVE-2026-20026 be exploited without authentication?
Yes, CVE-2026-20026 can be exploited by unauthenticated remote attackers.