Unrated severityNVD Advisory· Published Mar 4, 2026· Updated Mar 4, 2026
Cisco Secure Firewall Threat Defense Software Snort 3 Visual Basic for Application Infinite Loop Denial of Service Vulnerability
CVE-2026-20054
Description
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to enter an infinite loop, causing a DoS condition.
Affected products
4- Cisco/Cisco Cyber Visionv5Range: 3.0.0
- Cisco/Cisco Secure Firewall Threat Defense (FTD) Softwarev5Range: 7.2.0
- Cisco/Cisco UTD SNORT IPS Engine Softwarev5Range: 3.17.1S
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.