Cisco Snort3 DCE/RPC OOB Read Leak via DCE/RPC Buff Overflow
CVE-2026-20027 Published on January 7, 2026
Cisco Snort DCERPC Stub Data Out of Bounds Read
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection.
This vulnerability is due to an error in buffer handling logic when processing DCE/RPC requests, which can result in a buffer out-of-bounds read. An attacker could exploit this vulnerability by sending a large number of DCE/RPC requests through an established connection that is inspected by Snort 3. A successful exploit could allow the attacker to obtain sensitive information in the Snort 3 data stream.
Vulnerability Analysis
CVE-2026-20027 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-20027 has been classified to as an Information Disclosure vulnerability or weakness.
Affected Versions
Cisco Secure Firewall Threat Defense (FTD) Software:- Version 7.0.0 is affected.
- Version 7.0.0.1 is affected.
- Version 7.0.1 is affected.
- Version 7.1.0 is affected.
- Version 7.0.1.1 is affected.
- Version 7.1.0.1 is affected.
- Version 7.0.2 is affected.
- Version 7.2.0 is affected.
- Version 7.0.2.1 is affected.
- Version 7.0.3 is affected.
- Version 7.1.0.2 is affected.
- Version 7.2.0.1 is affected.
- Version 7.0.4 is affected.
- Version 7.2.1 is affected.
- Version 7.0.5 is affected.
- Version 7.3.0 is affected.
- Version 7.2.2 is affected.
- Version 7.2.3 is affected.
- Version 7.3.1 is affected.
- Version 7.1.0.3 is affected.
- Version 7.2.4 is affected.
- Version 7.0.6 is affected.
- Version 7.2.5 is affected.
- Version 7.2.4.1 is affected.
- Version 7.3.1.1 is affected.
- Version 7.4.0 is affected.
- Version 7.0.6.1 is affected.
- Version 7.2.5.1 is affected.
- Version 7.4.1 is affected.
- Version 7.2.6 is affected.
- Version 7.0.6.2 is affected.
- Version 7.4.1.1 is affected.
- Version 7.2.7 is affected.
- Version 7.2.5.2 is affected.
- Version 7.3.1.2 is affected.
- Version 7.2.8 is affected.
- Version 7.6.0 is affected.
- Version 7.4.2 is affected.
- Version 7.2.8.1 is affected.
- Version 7.0.6.3 is affected.
- Version 7.4.2.1 is affected.
- Version 7.2.9 is affected.
- Version 7.0.7 is affected.
- Version 7.7.0 is affected.
- Version 7.4.2.2 is affected.
- Version 7.2.10 is affected.
- Version 7.6.1 is affected.
- Version 7.4.2.3 is affected.
- Version 7.0.8 is affected.
- Version 7.6.2 is affected.
- Version 7.7.10 is affected.
- Version 7.0.8.1 is affected.
- Version 7.6.2.1 is affected.
- Version 7.7.10.1 is affected.
- Version 7.4.2.4 is affected.
- Version 7.2.10.2 is affected.
- Version 7.4.3 is affected.
- Version 3.17.1S is affected.
- Version 16.12.3 is affected.
- Version Fuji-16.9.5 is affected.
- Version 16.12.4 is affected.
- Version 17.3.1a is affected.
- Version 16.6.6 is affected.
- Version 16.12.2 is affected.
- Version Fuji-16.9.6 is affected.
- Version 3.17.0S is affected.
- Version Fuji-16.9.3 is affected.
- Version Denali-16.3.7 is affected.
- Version Fuji-16.9.2 is affected.
- Version Fuji-16.9.4 is affected.
- Version Everest-16.6.4 is affected.
- Version Everest-16.6.3 is affected.
- Version 16.6.5 is affected.
- Version Denali-16.3.5 is affected.
- Version 17.2.1r is affected.
- Version 17.1.1 is affected.
- Version Everest-16.6.2 is affected.
- Version 16.6.7a is affected.
- Version Denali-16.3.4 is affected.
- Version 16.6.1 is affected.
- Version Denali-16.3.9 is affected.
- Version Denali-16.3.3 is affected.
- Version 16.12.1a is affected.
- Version 17.3.2 is affected.
- Version 17.4.1a is affected.
- Version 16.12.5 is affected.
- Version 17.5.1 is affected.
- Version Fuji-16.9.7 is affected.
- Version 16.6.9 is affected.
- Version 17.3.3 is affected.
- Version 17.5.1a is affected.
- Version 17.3.4 is affected.
- Version 17.3.4a is affected.
- Version 17.4.2 is affected.
- Version 17.4.1b is affected.
- Version 17.6.1a is affected.
- Version 16.6.10 is affected.
- Version 17.7.1a is affected.
- Version 16.12.6 is affected.
- Version Fuji-16.9.8 is affected.
- Version 17.6.2 is affected.
- Version 17.8.1a is affected.
- Version 16.12.7 is affected.
- Version 17.3.5 is affected.
- Version 17.6.3 is affected.
- Version 17.6.3a is affected.
- Version 17.7.2 is affected.
- Version 17.9.1a is affected.
- Version 17.6.4 is affected.
- Version 17.10.1a is affected.
- Version 17.3.6 is affected.
- Version 16.12.8 is affected.
- Version 17.3.7 is affected.
- Version 17.9.2a is affected.
- Version 17.6.5 is affected.
- Version 17.11.1a is affected.
- Version 17.9.3a is affected.
- Version 17.12.1a is affected.
- Version 17.9.4 is affected.
- Version 17.6.6 is affected.
- Version 17.3.8 is affected.
- Version 17.3.8a is affected.
- Version 17.6.6a is affected.
- Version 17.9.4a is affected.
- Version 17.12.2 is affected.
- Version 17.13.1a is affected.
- Version 17.9.5a is affected.
- Version 17.12.3 is affected.
- Version 17.6.7 is affected.
- Version 17.14.1a is affected.
- Version 17.12.4 is affected.
- Version 17.12.3a is affected.
- Version 17.15.1a is affected.
- Version 17.6.8 is affected.
- Version 17.9.6 is affected.
- Version 17.6.8a is affected.
- Version 17.16.1a is affected.
- Version 17.9.5e is affected.
- Version 17.12.4a is affected.
- Version 17.15.2c is affected.
- Version 17.9.5f is affected.
- Version 17.12.4b is affected.
- Version 17.15.2a is affected.
- Version 17.12.5 is affected.
- Version 17.17.1 is affected.
- Version 17.12.5a is affected.
- Version 17.9.7a is affected.
- Version 17.15.3a is affected.
- Version 17.15.3 is affected.
- Version 17.12.5b is affected.
- Version 17.12.5c is affected.
- Version 17.15.4 is affected.
- Version 17.9.7b is affected.
- Version 17.18.1 is affected.
- Version 17.18.1a is affected.
- Version 17.12.6 is affected.
- Version 17.9.8 is affected.
- Version 17.15.4c is affected.
- Version 17.12.5d is affected.
- Version 17.18.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.