PT-2026-2047 · Snort+1 · Snort 3 Detection Engine+1

Guy Lederfein

·

Published

2026-01-07

·

Updated

2026-01-28

·

CVE-2026-20027

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco products (affected versions not specified)
Description A flaw exists in the processing of DCE/RPC requests that may allow a remote attacker to obtain sensitive information or cause the Snort 3 Detection Engine to restart, leading to an interruption of packet inspection. This is due to an error in buffer handling logic when processing DCE/RPC requests, resulting in a buffer out-of-bounds read. An attacker could exploit this by sending numerous DCE/RPC requests through an established connection inspected by Snort 3. The vulnerability could allow an attacker to obtain sensitive information from the Snort 3 data stream.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-01756
CVE-2026-20027
ZDI-26-045

Affected Products

Cisco Products
Snort 3 Detection Engine