Cisco Releases Security Update for Snort Ethernet Frame Decoder Denial of Service Vulnerability
Affected platforms
The following platforms are known to be affected:
This vulnerability affects the following Cisco products, if they are running a vulnerable release of Cisco UTD Snort IPS Engine Software for IOS XE or Cisco UTD Engine for IOS XE SD-WAN Software and are configured to pass Ethernet frames to the Snort detection engine:
1000 Series Integrated Services Routers (ISRs)
4000 Series Integrated Services Routers (ISRs)
Catalyst 8000V Edge Software
Catalyst 8200 Series Edge Platforms
Catalyst 8300 Series Edge Platforms
Cloud Services Router 1000V Series
Integrated Services Virtual Router (ISRv)
Threat details
Introduction
Cisco has released a security update to address vulnerabilities in Cisco UTD Snort IPS Engine Software for IOS XE and Cisco UTD Engine for IOS XE SD-WAN Software1. A remote attacker could exploit these vulnerabilities to obtain sensitive information.
Remediation advice
Organisations are encouraged to review Cisco security advisory cisco-sa-snort-ethernet-dos-HGXgJH8n and apply any relevant updates.
Last edited: 11 March 2021 12:19 pm