ZDI-CAN-27893: ZDI-26-045: Cisco Snort _bnfa_search_csparse_nfa Out-Of-Bounds Read Information Disclosure Vulnerability
Published Jan 28, 2026
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Snort. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-20027.
Affected Software
1 affected component
Cisco Snort
Event History
Jan 28, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-27893?
The severity of ZDI-CAN-27893 is rated as high due to the potential for sensitive information disclosure.
2
How do I fix ZDI-CAN-27893?
To fix ZDI-CAN-27893, update Cisco Snort to the latest version that addresses the vulnerability.
3
What types of information can be disclosed by exploiting ZDI-CAN-27893?
Exploiting ZDI-CAN-27893 may lead to the disclosure of sensitive information processed by Cisco Snort.
4
Is authentication required to exploit ZDI-CAN-27893?
No, authentication is not required to exploit ZDI-CAN-27893.
5
Which software is affected by ZDI-CAN-27893?
ZDI-CAN-27893 affects Cisco Snort installations that are unpatched.