
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2025-20217) was discovered in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software. The vulnerability was first published on August 14, 2025, and affects Cisco devices running vulnerable releases of Cisco Secure FTD Software with an intrusion policy enabled that has the Snort 3 engine running. This high-severity vulnerability has been assigned a CVSS base score of 8.6 (Cisco Advisory).
The vulnerability (CWE-835) is caused by incorrect processing of traffic that is inspected by an affected device. The issue specifically relates to a Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability. The vulnerability has been assigned a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H, indicating network accessibility, low attack complexity, and no required privileges or user interaction (NVD, Cisco Advisory).
A successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The attack can cause the affected device to enter an infinite loop while inspecting traffic, though the system watchdog will automatically restart the Snort process (Cisco Advisory).
Cisco has released software updates that address this vulnerability. There are no workarounds available for this vulnerability. Customers with service contracts should obtain security fixes through their usual update channels. The Cisco Software Checker can help customers determine their exposure to vulnerabilities and identify the appropriate software updates (Cisco Advisory).
The vulnerability was included in Cisco's August 2025 Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication, which addressed multiple security issues. Security researchers and news outlets have highlighted this vulnerability among other high-severity issues in the bundle (Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."