Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities (CVE-2025-20359 and CVE-2025-20360)
CVE numbers = CVE-2025-20359 and CVE-2025-20360
Multiple Cisco products are affected by vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak possible sensitive information or to restart.
Open Source Snort 3
At the time of publication, these vulnerabilities affected Open Source Snort 3.
For information about which Snort releases were vulnerable at the time of publication, see the Fixed Software section of this advisory. For more information on Snort, see the Snort website.
Cisco Secure Firewall Threat Defense Software
At the time of publication, these vulnerabilities affected Cisco Secure Firewall Threat Defense (FTD) Software if Snort 3 was configured.
For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory.
Determine the Snort Configuration on Cisco Secure FTD Software
On new installations of Cisco Secure FTD Software releases 7.0.0 and later, Snort 3 is running by default. On devices that were running Cisco Secure FTD Software Release 6.7.0 or earlier and were upgraded to Release 7.0.0 or later, Snort 2 is running by default.
To determine if Snort 3 is running on Cisco Secure FTD Software, see Determine the Active Snort Version that Runs on Firepower Threat Defense (FTD). Snort 3 must be active for these vulnerabilities to be exploited.
Cisco IOS XE Software
At the time of publication, these vulnerabilities affected the following Cisco products if they were running a vulnerable release of Unified Threat Defense (UTD) Snort IPS Engine for Cisco IOS XE Software or UTD Engine for Cisco IOS XE SD-WAN Software:
- 1000 Series Integrated Services Routers (ISRs)
- 4000 Series ISRs
- Catalyst 8000V Edge Software
- Catalyst 8200 Series Edge Platforms
- Catalyst 8300 Series Edge Platforms
- Catalyst 8500L Edge Platforms
- Cloud Services Routers 1000V
- Integrated Services Virtual Routers
Note: UTD is not installed on these devices by default. If the UTD file is not installed, the device is not affected by these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-mime-vulns-tTL8PgVH

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
