{"id":"CVE-2026-20052","title":"A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.\r\n…","summary":"A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.\r\n…","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","cwe":["CWE-788"],"vendor":"cisco","product":"secure_firewall_threat_defense","affected":["secure_firewall_threat_defense = 7.4.0","secure_firewall_threat_defense = 7.4.1","secure_firewall_threat_defense = 7.4.1.1","secure_firewall_threat_defense = 7.4.2","secure_firewall_threat_defense = 7.4.2.1","secure_firewall_threat_defense = 7.6.0"],"published":"2026-03-04","updated":"2026-08-20","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20052","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort3ssl-FBEKYXpH","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00413,"epssPercentile":0.35207,"ingestedAt":"2026-08-20T17:59:04.079Z","slug":"CVE-2026-20052","body":"## Overview\n\nA vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart.\r\n\r\nThis vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet inspection. An attacker could exploit this vulnerability by sending crafted SSL packets&nbsp;through an established connection to be parsed by the Snort 3 Detection Engine. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when the Snort 3 Detection Engine unexpectedly restarts.\n\n## Affected\n\n- `secure_firewall_threat_defense = 7.4.0`\n- `secure_firewall_threat_defense = 7.4.1`\n- `secure_firewall_threat_defense = 7.4.1.1`\n- `secure_firewall_threat_defense = 7.4.2`\n- `secure_firewall_threat_defense = 7.4.2.1`\n- `secure_firewall_threat_defense = 7.6.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}