Unrated severityNVD Advisory· Published Mar 4, 2026· Updated Mar 4, 2026
Cisco Secure Firewall Threat Defense Software Snort 3 Visual Basic for Application Denial of Service Vulnerability
CVE-2026-20057
Description
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending a crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart causing a a denial of service (DoS) condition.
Affected products
4- Cisco/Cisco Cyber Visionv5Range: 3.0.0
- Cisco/Cisco Secure Firewall Threat Defense (FTD) Softwarev5Range: 7.2.0
- Cisco/Cisco UTD SNORT IPS Engine Softwarev5Range: 17.12.1a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.