Description
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in buffer handling logic when processing DCE/RPC requests, which can result in a buffer out-of-bounds read. An attacker could exploit this vulnerability by sending a large number of DCE/RPC requests through an established connection that is inspected by Snort 3. A successful exploit could allow the attacker to obtain sensitive information in the Snort 3 data stream.
Problem types
Exposure of Sensitive Information to an Unauthorized Actor
Product status
7.0.0
7.0.0.1
7.0.1
7.1.0
7.0.1.1
7.1.0.1
7.0.2
7.2.0
7.0.2.1
7.0.3
7.1.0.2
7.2.0.1
7.0.4
7.2.1
7.0.5
7.3.0
7.2.2
7.2.3
7.3.1
7.1.0.3
7.2.4
7.0.6
7.2.5
7.2.4.1
7.3.1.1
7.4.0
7.0.6.1
7.2.5.1
7.4.1
7.2.6
7.0.6.2
7.4.1.1
7.2.7
7.2.5.2
7.3.1.2
7.2.8
7.6.0
7.4.2
7.2.8.1
7.0.6.3
7.4.2.1
7.2.9
7.0.7
7.7.0
7.4.2.2
7.2.10
7.6.1
7.4.2.3
7.0.8
7.6.2
7.7.10
7.0.8.1
7.6.2.1
7.7.10.1
7.4.2.4
7.2.10.2
7.4.3
3.17.1S
16.12.3
Fuji-16.9.5
16.12.4
17.3.1a
16.6.6
16.12.2
Fuji-16.9.6
3.17.0S
Fuji-16.9.3
Denali-16.3.7
Fuji-16.9.2
Fuji-16.9.4
Everest-16.6.4
Everest-16.6.3
16.6.5
Denali-16.3.5
17.2.1r
17.1.1
Everest-16.6.2
16.6.7a
Denali-16.3.4
16.6.1
Denali-16.3.9
Denali-16.3.3
16.12.1a
17.3.2
17.4.1a
16.12.5
17.5.1
Fuji-16.9.7
16.6.9
17.3.3
17.5.1a
17.3.4
17.3.4a
17.4.2
17.4.1b
17.6.1a
16.6.10
17.7.1a
16.12.6
Fuji-16.9.8
17.6.2
17.8.1a
16.12.7
17.3.5
17.6.3
17.6.3a
17.7.2
17.9.1a
17.6.4
17.10.1a
17.3.6
16.12.8
17.3.7
17.9.2a
17.6.5
17.11.1a
17.9.3a
17.12.1a
17.9.4
17.6.6
17.3.8
17.3.8a
17.6.6a
17.9.4a
17.12.2
17.13.1a
17.9.5a
17.12.3
17.6.7
17.14.1a
17.12.4
17.12.3a
17.15.1a
17.6.8
17.9.6
17.6.8a
17.16.1a
17.9.5e
17.12.4a
17.15.2c
17.9.5f
17.12.4b
17.15.2a
17.12.5
17.17.1
17.12.5a
17.9.7a
17.15.3a
17.15.3
17.12.5b
17.12.5c
17.15.4
17.9.7b
17.18.1
17.18.1a
17.12.6
17.9.8
17.15.4c
17.12.5d
17.18.2
References
sec.cloudapps.cisco.com/...o-sa-snort3-dcerpc-vulns-J9HNF4tH (cisco-sa-snort3-dcerpc-vulns-J9HNF4tH)