Skip to main content

Cisco Releases Security Update for Snort Ethernet Frame Decoder Denial of Service Vulnerability

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

This vulnerability affects the following Cisco products, if they are running a vulnerable release of Cisco UTD Snort IPS Engine Software for IOS XE or Cisco UTD Engine for IOS XE SD-WAN Software and are configured to pass Ethernet frames to the Snort detection engine:

1000 Series Integrated Services Routers (ISRs)

4000 Series Integrated Services Routers (ISRs)

Catalyst 8000V Edge Software

Catalyst 8200 Series Edge Platforms

Catalyst 8300 Series Edge Platforms

Cloud Services Router 1000V Series

Integrated Services Virtual Router (ISRv)


Threat details

Introduction

Cisco has released a security update to address vulnerabilities in Cisco UTD Snort IPS Engine Software for IOS XE and Cisco UTD Engine for IOS XE SD-WAN Software1. A remote attacker could exploit these vulnerabilities to obtain sensitive information.


Remediation advice

Organisations are encouraged to review Cisco security advisory cisco-sa-snort-ethernet-dos-HGXgJH8n and apply any relevant updates.

Last edited: 11 March 2021 12:19 pm