CNNVD-202601-1194 Information

CNNVD ID

CNNVD-202601-1194

CVE-2026-20026

  • CNNVD Published: 2026-01-07

Description (Chinese)

Cisco UTD SNORT IPS Engine Software和Cisco Secure Firewall Threat Defense Software都是美国思科(Cisco)公司的产品。Cisco UTD SNORT IPS Engine Software是一个入侵检测与防御引擎。Cisco Secure Firewall Threat Defense Software是一个防火墙操作系统。 Cisco UTD SNORT IPS Engine Software和Cisco Secure Firewall Threat Defense Software存在资源管理错误漏洞,该漏洞源于处理DCE/RPC请求时的缓冲区处理逻辑错误,可能导致缓冲区释放后重用读取,造成拒绝服务。

Description (English)

Cisco UTD SNORT IPS Engineering Software and Cisco Security Fairwall Threat Defense Software are all Cisco products. Cisco UTD SNORT IPS Engineering Software is an intrusion detection and defense engine. Cisco Secure Fairewall. Cisco UTD SNORT IPSS Engineering Software and Cisco Security Fairwall Threat Defense Software had a resource management error that stemmed from a logical error in the handling of the buffer zone at the time of the DCE/RPC request, which could lead to the re-reading of the buffer zone after its release, resulting in the denial of services.

Hazard Level

High

Vulnerability Type

资源管理错误

Affected Vendor

思科

Published

2026-01-07

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-dcerpc-vulns-J9HNF4tH

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-dcerpc-vulns-J9HNF4tH

Share on: