CVE-2026-20052: Cisco Secure Firewall Threat Defense Software Snort 3 Memory Management Denial of Service Vulnerability
A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet inspection. An attacker could exploit this vulnerability by sending crafted SSL packets through an established connection to be parsed by the Snort 3 Detection Engine. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when the Snort 3 Detection Engine unexpectedly restarts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20052?
CVE-2026-20052 has been classified as a critical severity vulnerability.
How do I fix CVE-2026-20052?
To mitigate CVE-2026-20052, upgrade to the latest version of Cisco Secure Firewall Threat Defense software that addresses this vulnerability.
Who is affected by CVE-2026-20052?
CVE-2026-20052 affects all versions of Cisco Secure Firewall Threat Defense Software utilizing the Snort 3 Detection Engine.
Can CVE-2026-20052 be exploited remotely?
Yes, CVE-2026-20052 can be exploited by an unauthenticated, remote attacker.
What are the potential impacts of CVE-2026-20052?
Exploitation of CVE-2026-20052 could lead to a denial of service condition, affecting the availability of the firewall services.