Record summary

CVE-2026-20067 has a selected CVSS score of 5.8 (medium).

Description

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection.  This vulnerability is due to incomplete error checking when parsing the Multicast DNS fields of the HTTP header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition when the Snort 3 Detection Engine unexpectedly restarts.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE List3.0.0affected
3.0.2affected
3.0.3affected
3.0.1affected
3.1.0affected
3.0.4affected
3.1.1affected
3.1.2affected
3.2.0affected
3.0.5affected
3.2.1affected
3.0.6affected
Showing 12 of 54 version ranges

Cisco Secure Firewall Threat Defense (FTD) Software

Browse Cisco / Cisco Secure Firewall Threat Defense (FTD) Software

Default status: unknown

CVE List7.0.0affected
7.0.0.1affected
7.0.1affected
7.1.0affected
7.0.1.1affected
7.1.0.1affected
7.0.2affected
7.2.0affected
7.0.2.1affected
7.0.3affected
7.1.0.2affected
7.2.0.1affected
Showing 12 of 57 version ranges

Cisco UTD SNORT IPS Engine Software

Browse Cisco / Cisco UTD SNORT IPS Engine Software

Default status: unknown

CVE List17.3.1aaffected
17.2.1raffected
17.3.2affected
17.4.1aaffected
17.5.1affected
17.3.3affected
17.5.1aaffected
17.3.4affected
17.3.4aaffected
17.4.2affected
17.4.1baffected
17.6.1aaffected
Showing 12 of 71 version ranges

References

2