Buffer Access with Incorrect Length Value in Snort - CVE-2025-20360

 

Buffer Access with Incorrect Length Value in Snort - CVE-2025-20360

Published: October 15, 2025


Vulnerability identifier: #VU117302
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20360
CWE-ID: CWE-805
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the HTTP decoder when handling MIME fields. A remote attacker can send specially crafted HTTP packets through the channel that is monitored by the application and perform a denial of service (DoS) attack.


Affected software

Snort
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cyber Vision
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2025-20360

Install updates from vendor's website.

Snort - update to 3.9.1.0
Cisco Firewall Threat Defense (FTD) - addressed in versions 7.4.3, 7.6.2, 7.7.10
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - addressed in versions 7.4.3, 7.6.2, 7.7.10

External References

Related Security Bulletins