Buffer under-read in Snort - CVE-2025-20359

 

Buffer under-read in Snort - CVE-2025-20359

Published: October 15, 2025


Vulnerability identifier: #VU117301
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20359
CWE-ID: CWE-127
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the HTTP decoder when handling MIME fields. A remote attacker can send specially crafted HTTP packets through the channel that is monitored by the application and perform a denial of service (DoS) attack.


Affected software

Snort
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cyber Vision
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2025-20359

Install updates from vendor's website.

Snort - update to 3.9.3.0
Cisco Firewall Threat Defense (FTD) - addressed in versions 7.4.3, 7.6.2, 7.7.10
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - addressed in versions 7.4.3, 7.6.2, 7.7.10

External References

Related Security Bulletins