Multiple Cisco Products Snort 3 VBA Decompression DoS (cisco-sa-ftd-snort3-vbavuls-96UcVVed)

medium Nessus Plugin ID 311459

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Secure Firewall Threat Defense (FTD) Software is affected by multiple vulnerabilities.

- Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause an overflow of heap data, which could cause a DoS condition. (CVE-2026-20053)

- Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper handling of VBA data during decompression. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart, causing a DoS condition. (CVE-2026-20054)

- Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart, causing a DoS condition. (CVE-2026-20057)

- Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart, causing a DoS condition. (CVE-2026-20058)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwq23369, CSCwq23372, CSCwq23373, CSCwq23377

See Also

http://www.nessus.org/u?39d02a28

http://www.nessus.org/u?73afe95c

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq23369

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq23372

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq23373

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq23377

Plugin Details

Severity: Medium

ID: 311459

File Name: cisco-sa-ftd-snort3-vbavuls-96UcVVed-ftd.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 5/1/2026

Updated: 5/1/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-20058

CVSS v3

Risk Factor: Medium

Base Score: 5.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Vulnerability Information

CPE: cpe:/o:cisco:firepower_threat_defense

Required KB Items: installed_sw/Cisco Firepower Threat Defense

Patch Publication Date: 3/4/2026

Vulnerability Publication Date: 3/4/2026

Reference Information

CVE: CVE-2026-20053, CVE-2026-20054, CVE-2026-20057, CVE-2026-20058