Impact
Suricata's FTP parser incorrectly treats a RETR or STOR command issued before the data transfer mode negotiation (PORT or PASV) as a fatal application‑layer error. This causes the parser to enter a fatal state and disables further FTP parsing for the entire remaining TCP flow. As a result, any subsequent FTP commands pass through the IDS/IPS engine without application‑layer inspection, allowing an attacker to evade parser‑dependent detection rules or logging. The vulnerability does not grant direct code execution but reduces the effectiveness of IDS/IPS monitoring for the affected session.
Affected Systems
OISF Suricata versions earlier than 8.0.6 are impacted. The flaw resides in the FTP component of the Suricata engine and was corrected in the 8.0.6 release.
Risk and Exploitability
The CVSS score of 3.7 indicates moderate severity. EPSS is unavailable and the issue is not listed in CISA’s KEV catalogue. The vulnerability can be exploited by any external party that can establish an FTP session to the Suricata‑protected network. By sending a RETR or STOR command before initiating data transfer mode, an attacker can force Suricata to discard further session inspection, thereby suppressing detection of later commands. The attack does not require privileged access to the Suricata host, and the impact is limited to the specific file transfer session.
OpenCVE Enrichment