CNNVD-202601-1193 Information

CNNVD ID

CNNVD-202601-1193

CVE-2026-20027

  • CNNVD Published: 2026-01-07

Description (Chinese)

Cisco Secure Firewall Threat Defense和Cisco UTD SNORT IPS Engine Software都是美国思科(Cisco)公司的产品。Cisco Secure Firewall Threat Defense是一个集成式防火墙平台。Cisco UTD SNORT IPS Engine Software是一个入侵检测与防御引擎。 Cisco Secure Firewall Threat Defense和Cisco UTD SNORT IPS Engine Software存在信息泄露漏洞,该漏洞源于处理DCE/RPC请求时缓冲区处理逻辑存在错误,可能导致缓冲区越界读取,从而造成敏感信息泄露或服务中断。

Description (English)

Cisco Security Fairwall Threat Defense and Cisco UTD SNORT IPS Engineering Software are all Cisco products. Cisco Security Firewall Threat Defense is an integrated firewall platform. Cisco UTD SNORT IPS Engineering Software is an intrusion detection and defense engine. Cisco Secure Fairwall Threat Defense and Cisco UTD SNORT IPS Engineering Software have information leaks, which stem from errors in the logic of the handling of the buffer zone at the time of DCE/RPC requests, which may lead to cross-border access to the buffer zone, leading to the disclosure of sensitive information or disruption of services.

Hazard Level

High

Vulnerability Type

信息泄露

Affected Vendor

思科

Published

2026-01-07

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-dcerpc-vulns-J9HNF4tH

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-dcerpc-vulns-J9HNF4tH

Share on: