Security News > 2021 > March > Several Cisco Products Exposed to DoS Attacks Due to Snort Vulnerability

Several Cisco Products Exposed to DoS Attacks Due to Snort Vulnerability
2021-03-04 13:46

Cisco informed customers on Wednesday that several of its products are exposed to denial-of-service attacks due to a vulnerability in the Snort detection engine.

Cisco says the vulnerability is in the Ethernet Frame Decoder component of Snort.

These devices are affected if they are running a vulnerable version of Cisco UTD Snort IPS engine software for IOS XE or Cisco UTD Engine for IOS XE SD-WAN, and they are configured to pass Ethernet frames to Snort.

Cisco says the vulnerability is related to a Firepower Threat Defense issue patched in October 2020.

The vulnerability was found during the resolution of a support case and there is no evidence that it has been exploited in malicious attacks.

Cisco on Wednesday also published advisories for a dozen other vulnerabilities, which have been assigned a medium severity rating.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/8UDxQwtE38U/several-cisco-products-exposed-dos-attacks-due-snort-vulnerability

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4448 233 3130 1874 610 5847
Snort 1 0 10 6 2 18