Description
A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.

This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.
Published: 2026-09-16
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Snort 2 engine restart
Action: Apply Patch
AI Analysis

Impact

A remote, unauthenticated attacker can send a crafted SSL/TLS connection setup request that is parsed by the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense. The engine contains an incomplete validation of the SSL certificate, and when it processes the malformed request the Snort 2 Detection Engine restarts unexpectedly. The restart temporarily disables the firewall’s packet inspection and routing capability, causing a denial‑of‑service condition for traffic routed through the device.

Affected Systems

Cisco Secure Firewall Threat Defense (FTD) Software, specifically the Snort 2 Detection Engine. No specific version information is disclosed, so any released product that incorporates this engine is potentially vulnerable.

Risk and Exploitability

The CVSS base score is 5.8, indicating a moderate impact, while the EPSS of less than 1 % suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to forge a valid‑looking SSL/TLS handshake and target the firewall from outside the network, implying a remote, unauthenticated attack vector.

Generated by OpenCVE AI on September 18, 2026 at 01:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Cisco Secure Firewall Threat Defense (FTD) Software release that contains the patched Snort 2 engine
  • If immediate upgrade is not possible, segregate the firewall from external networks and block the ports used by SSL/TLS handshakes destined for the Snort 2 engine
  • Monitor firewall logs for unexpected restarts or packet inspection errors and apply additional mitigations as needed

Generated by OpenCVE AI on September 18, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.
Title Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability
Weaknesses CWE-805
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Cisco Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T17:29:41.938Z

Reserved: 2025-10-08T11:59:15.405Z

Link: CVE-2026-20290

cve-icon Vulnrichment

Updated: 2026-09-17T17:25:37.891Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:09.610

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:11:46Z

Weaknesses
  • CWE-805

    Buffer Access with Incorrect Length Value