logo

Blinding Snort IDS/IPS: Breaking the Modbus OT Preprocessor

ID: ad650e29-4cef-598d-967b-bfddb591fa48

STIX ID: report--ad650e29-4cef-598d-967b-bfddb591fa48

Feed Name: Claroty Team82

Threat Score
70/100

Date Published: 2023-08-16

Date Updated: 2026-04-17

Author: Uri Katz

...
...

Team82 discovered CVE-2022-20685, an integer-overflow vulnerability in the Snort Modbus OT preprocessor that can be exploited remotely to trigger an infinite while-loop, causing a denial-of-service that prevents Snort from processing packets or generating alerts; the issue affects open-source Snort releases earlier than 2.9.19 and 3.1.11.0, has a CVSSv3 score of 7.5 (CWE-190), and has been patched by Cisco and the Snort team.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.