Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
TL;DR 📌
Multiple Cisco products are affected by vulnerabilities in the Snort 3 MIME Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or restart, leading to a denial of service. Cisco has released software updates to address these vulnerabilities, but no workarounds are available.
What happened 🕵️♂️
Cisco has identified vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder within Snort 3, which could be exploited by an unauthenticated remote attacker. These vulnerabilities may lead to the disclosure of sensitive information or cause the Snort 3 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.
Affected products 🖥️
The following products are affected by these vulnerabilities:
- Open Source Snort 3
- Cisco Secure Firewall Threat Defense Software (if Snort 3 is configured)
- Cisco IOS XE Software (if running a vulnerable release of Unified Threat Defense Snort IPS Engine)
- Cisco Meraki products (specific models listed in the advisory)
- Cisco Cyber Vision
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3.x | 3.9.1.0 | |
| 5.2 | Migrate to a fixed release. | |
| 5.3 | Not vulnerable. | |
| 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available for these vulnerabilities.
Risk in context 🎯
The vulnerabilities present a medium risk (CVSS score of 6.5) due to the potential for information disclosure and denial of service. The attack vector is unauthenticated and remote, which increases the likelihood of exploitation. Organizations using affected Cisco products should prioritize applying the available patches to mitigate the risks.
Fast facts ⚡
- CVSS Score: 6.5 (Medium)
- Vulnerabilities: CVE-2025-20359 and CVE-2025-20360
- Impact: Information disclosure and denial of service
- Workarounds: None available
- Fixed Software: Available for specific versions of Snort 3 and Cisco Secure Firewall
For leadership 🧭
Executive summary. Firewalls and industrial security appliances running Snort 3 for inspection can be knocked into a restart loop or coaxed into leaking data by an attacker who needs no login and no special access. There is no workaround, so the only path to closing this off is patching, and it should be scheduled promptly given the unauthenticated remote attack path.
Why it matters:
- The Snort 3 Detection Engine sits inline on traffic through Firepower 1000/2100/4100 Series and the 3000 Series Industrial Security Appliances, so a crash there can disrupt inspection on production and OT-adjacent links.
- Both flaws require no authentication and can be triggered remotely, which is a lower bar for an attacker than most vulnerabilities affecting this class of device.
- One of the two issues can disclose sensitive information rather than just cause a restart, giving an attacker a foothold beyond simple disruption.
- Cisco has not published a workaround, so devices remain exposed until the underlying software is upgraded.
Now / Next / Later:
- Now: Identify every Cisco 3000 Series ISA, Cyber Vision instance, and Firepower 1000/2100/4100 Series device running Snort 3 to confirm which are exposed to CVE-2025-20359 and CVE-2025-20360.
- Next: Schedule upgrades to the first fixed release for each affected train during the next maintenance window, since no interim workaround exists to reduce risk in the meantime.
- Later: Add Snort 3 version tracking to routine patch reviews for Firepower and Cyber Vision deployments so future decoder-level advisories are actioned without a separate discovery step.