CVE-2026-20027 Details
Description
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in buffer handling logic when processing DCE/RPC requests, which can result in a buffer out-of-bounds read. An attacker could exploit this vulnerability by sending a large number of DCE/RPC requests through an established connection that is inspected by Snort 3. A successful exploit could allow the attacker to obtain sensitive information in the Snort 3 data stream.
A vulnerability exists in multiple Cisco products running Snort 3, specifically in the processing of DCE/RPC requests. This issue could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, disrupting packet inspection. The vulnerability arises from improper buffer handling when processing DCE/RPC requests, leading to a buffer out-of-bounds read. Exploitation involves sending a high volume of DCE/RPC requests through an established connection that Snort 3 is inspecting, potentially allowing the attacker to access sensitive information within the Snort 3 data stream.
Cisco has released software updates to address this vulnerability. For Open Source Snort 3, users should upgrade to version 3.9.6.0. For Cisco Secure Firewall Threat Defense Software, hot fixes are available for versions 7.0 and 7.2. Cisco Meraki plans to release fixes in February 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 7, 2026CISA-ADP
Assessed Jan 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-dcerpc-vulns-J9HNF4tH | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cisco Snort 3 | All versions |
CPE
Remediation
| |
| Cisco Secure Firewall Threat Defense | All versions |
CPE
Remediation
| |
| Cisco 1000 Series Integrated Services Routers | All versions |
CPE
Remediation
| |
| Cisco 4000 Series Integrated Services Routers | All versions |
CPE
Remediation
| |
| Cisco Catalyst 8000V | All versions |
CPE
Remediation
| |
| Cisco Catalyst 8200 Series | All versions |
CPE
Remediation
| |
| Cisco Catalyst 8300 Series | All versions |
CPE
Remediation
| |
| Cisco Catalyst 8500L | All versions |
CPE
Remediation
| |
| Cisco Cloud Services Router 1000V | All versions |
CPE
Remediation
| |
| Cisco Integrated Services Virtual Routers | All versions |
CPE
Remediation
| |
| Cisco MX67 | All versions |
CPE
Remediation
| |
| Cisco MX67C | All versions |
CPE
Remediation
| |
| Cisco MX67W | All versions |
CPE
Remediation
| |
| Cisco MX68 | All versions |
CPE
Remediation
| |
| Cisco MX68CW | All versions |
CPE
Remediation
| |
| Cisco MX68W | All versions |
CPE
Remediation
| |
| Cisco MX75 | All versions |
CPE
Remediation
| |
| Cisco MX84 | All versions |
CPE
Remediation
| |
| Cisco MX85 | All versions |
CPE
Remediation
| |
| Cisco MX95 | All versions |
CPE
Remediation
| |
| Cisco MX100 | All versions |
CPE
Remediation
| |
| Cisco MX105 | All versions |
CPE
Remediation
| |
| Cisco MX250 | All versions |
CPE
Remediation
| |
| Cisco MX400 | All versions |
CPE
Remediation
| |
| Cisco MX450 | All versions |
CPE
Remediation
| |
| Cisco MX600 | All versions |
CPE
Remediation
| |
| Cisco MX Z4 | All versions |
CPE
Remediation
| |
| Cisco MX vMX | All versions |
CPE
Remediation
| |
| Cisco IOS XE | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 7, 2026 | New CVE Received | [email protected] |
Volerion