Cisco Secure Firewall Threat Defense Software Snort 3 Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

A high-severity denial of service (DoS) vulnerability has been identified in the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense Software. An unauthenticated remote attacker can exploit this issue, leading to potential service disruptions. Cisco has released software updates to address this vulnerability, but no workarounds are available.

What happened 🕵️‍♂️

A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition on affected devices. This issue arises from incorrect processing of traffic being inspected, which can lead to an infinite loop during traffic inspection. Although the system watchdog will automatically restart the Snort process, the vulnerability poses a significant risk of service interruption.

Affected products 🖥️

This vulnerability affects Cisco devices running a vulnerable release of Cisco Secure FTD Software with an enabled intrusion policy that utilizes the Snort 3 engine. For specific affected versions, refer to the Fixed Software section of the advisory.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The highest CVSS score for this vulnerability is 8.6, categorizing it as High severity. The exposure is significant as it allows unauthenticated remote access, potentially leading to service disruptions. Organizations should prioritize applying the available software updates to mitigate the risk of exploitation.

Fast facts ⚡

  • Vulnerability: Denial of Service in Snort 3 Detection Engine
  • CVSS Score: 8.6 (High)
  • Exploitation: Requires unauthenticated remote access
  • Workarounds: None available
  • Impact: Service disruption due to infinite loop during traffic inspection

For leadership 🧭

Executive summary. Firewalls running Cisco Secure Firewall Threat Defense with Snort 3 intrusion policies enabled can be knocked offline by remote traffic alone, with no credentials required and no workaround to fall back on. Given the 8.6 severity score and the fact that this sits on inline traffic-inspection devices, patching should be scheduled as a priority change rather than deferred to routine maintenance.

Why it matters:

  • The flaw is in the Snort 3 Detection Engine’s packet inspection path, meaning any traffic crossing an FTD device with an intrusion policy enabled is a potential trigger.
  • No authentication is needed, so exposure is defined purely by whether the firewall is inspecting traffic reachable by an attacker, which for most deployments is effectively all traffic passing through it.
  • Cisco has confirmed there is no workaround, so the only mitigation until upgrade is accepting the risk or restricting Snort 3-based intrusion policy use.
  • While the watchdog restarts the Snort process automatically, each trigger causes a gap in inspection and a service interruption on a device that is typically load-bearing for perimeter or segmentation security.

Now / Next / Later:

  • Now: Identify every Cisco Secure Firewall Threat Defense device running Snort 3 with an intrusion policy enabled and check its version against the Fixed Software table in the advisory.
  • Next: Schedule and apply the first fixed release for each affected train during your next change window, treating FTD units as high priority given the lack of any workaround.
  • Later: Build Cisco FTD Snort 3 patch tracking into routine firewall lifecycle reviews so fixed releases for detection-engine issues are applied on a predictable cadence rather than reactively.