Heap Inspection in Sourcefire products - CVE-2022-20922
Published: November 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of system resources in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
FirePOWER Services
Cyber Vision
Cisco Firewall Threat Defense (FTD)
Meraki MX Security Appliances
Snort
How to mitigate CVE-2022-20922
Snort - update to 3.1.31.0