Cisco Secure Firewall Threat Defense Software Snort 3 Denial of Service Vulnerability
TL;DR 📌
- A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of traffic that is inspected by an affected device.…
- Highest CVSS: 8.6 (High).
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2025-20217.
What it is
CVE-2025-20217 sits in the Snort 3 Detection Engine within Cisco Secure Firewall Threat Defense (FTD) Software. It affects the packet inspection path — the data plane component that examines traffic passing through the device against intrusion policies.
The flaw is caused by incorrect processing of certain traffic during inspection. An unauthenticated, remote attacker can send crafted traffic through the affected device to trigger it — no credentials or management access required, just the ability to route traffic through the firewall’s inspection engine.
A successful exploit causes the Snort 3 process to enter an infinite loop while inspecting the traffic, resulting in a denial of service. Cisco notes that the system watchdog will automatically restart the Snort process, so the outage is not permanent, but inspection (and therefore enforcement of intrusion policies) is disrupted while this happens.
The vulnerability only applies where Snort 3 is the active detection engine and an intrusion policy is enabled and running it. Cisco has confirmed that Secure Firewall ASA, Secure FMC, Cisco Cyber Vision, Meraki products, Umbrella, Cisco UTD, and both open-source Snort 2 and Snort 3 are not affected — this is specific to Snort 3 as integrated into FTD.
What to do
- Check whether Snort 3 is the active detection engine on your FTD devices using Cisco’s documented procedure (“Determine the Active Snort Version that Runs on Firepower Threat Defense (FTD)”). If Snort 2 is active, or no intrusion policy is enabled, the device is not exploitable via this path.
- There is no workaround. If Snort 3 is active with an intrusion policy enabled, the only mitigation is to install the fixed FTD release identified for your platform and train — consult the advisory’s Fixed Software section and use Cisco’s Software Checker against your specific release (e.g. 7.4.2-style version strings) to find the appropriate update.
- This advisory is bundled with the August 2025 semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software publication — worth reviewing the full bundle in case other advisories in that release also apply to your deployment.
- No workaround exists, but note the automatic watchdog recovery: plan patching during a maintenance window rather than treating this as an active-incident response, since Cisco PSIRT is not aware of any public exploitation.
For leadership 🧭
Executive summary. Firewalls running Cisco Secure FTD with the Snort 3 engine active can be knocked into a self-recovering denial of service by an unauthenticated attacker simply sending traffic through them, briefly halting intrusion policy enforcement. There is no workaround, so this needs a scheduled patch rather than an emergency response, since the watchdog restarts the process automatically and no exploitation has been observed.
Why it matters:
- Any unauthenticated remote party who can route traffic through an affected FTD device can trigger the fault — no credentials, VPN access, or management-plane reach is needed.
- Snort 3 entering an infinite loop stops packet inspection until the watchdog restarts it, meaning intrusion policy enforcement is briefly disabled on that path each time it’s triggered.
- The exposure only exists where Snort 3 is the active engine with an intrusion policy running — Snort 2 deployments, ASA, FMC, and several other Cisco products are explicitly unaffected.
- No workaround is available, so exposed devices remain triggerable repeatedly until the fixed FTD release is installed.
Now / Next / Later:
- Now: Run Cisco’s documented procedure to check whether Snort 3 is the active detection engine on each FTD device and whether an intrusion policy is enabled against it.
- Next: For any device confirmed to be running Snort 3 with an intrusion policy, install the fixed FTD release identified in the advisory’s Fixed Software section, using Cisco’s Software Checker against your exact version string.
- Later: Track this fix alongside the rest of the August 2025 semiannual Secure Firewall ASA/FMC/FTD advisory bundle so future upgrade cycles for these platforms are reviewed as a set rather than patch by patch.