CVE-2025-20217

8.6

Cisco · Secure Firewall Threat Defense (FTD) Software

A flaw in the Snort 3 engine of Cisco Secure Firewall FTD allows unauthenticated remote attackers to cause a denial of service via crafted traffic that triggers an infinite loop.

Executive summary

A critical vulnerability in the Cisco Secure Firewall Threat Defense Snort 3 engine allows unauthenticated remote attackers to trigger a denial of service condition.

Vulnerability

This vulnerability, categorized as CWE-835, stems from incorrect traffic processing within the Snort 3 Detection Engine. An unauthenticated remote attacker can exploit this by sending specifically crafted traffic that forces the engine into an infinite loop, causing a denial of service on the firewall device.

Business impact

The exploitation of this vulnerability results in a denial of service, which disrupts critical network security and traffic inspection capabilities. Given the CVSS score of 8.6, this flaw poses a high risk to business continuity, as the affected firewall may become unresponsive or require frequent automated restarts by the system watchdog, leading to intermittent network outages and security gaps.

Remediation

Immediate Action: Review the official Cisco security advisory for available firmware updates and apply the recommended patches to all affected FTD devices.

Proactive Monitoring: Monitor firewall system logs for recurring Snort process restarts or watchdog alerts that indicate potential exploitation attempts.

Compensating Controls: While a permanent patch is preferred, ensure that ingress traffic is strictly filtered at the network perimeter to reduce the volume of suspicious or malformed packets reaching the firewall.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing the affected versions of Cisco Secure Firewall Threat Defense must prioritize the application of vendor-supplied patches. Given the potential for automated exploitation of such network-level vulnerabilities, immediate remediation is necessary to prevent unauthorized service disruption and maintain the integrity of the network security perimeter.

More Cisco CVEs

Sources