Suricata is a widely deployed open-source network intrusion detection and prevention system that monitors traffic across enterprise and service-provider networks, making its security posture relevant to a significant installed base despite a narrow product portfolio. Vulnerabilities affecting this vendor have centered on the core Suricata engine itself, reflecting its role as a parser and pattern-matching system for network protocols. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Suricata Ids over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6794MEDIUM Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-wa | Feb 7, 2018 | 5.3 | 42 | NO | YES |
CVE-2019-10053CRITICAL An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buff | May 13, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-16411CRITICAL An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a | Sep 24, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-16410CRITICAL An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not alloc | Sep 24, 2019 | 9.1 | 28 | NO | NO |
CVE-2019-15699CRITICAL An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a me | Sep 24, 2019 | 9.1 | 28 | NO | NO |
CVE-2018-18956HIGH The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input | Nov 5, 2018 | 7.5 | 25 | NO | NO |
CVE-2019-10056HIGH An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function DecodeEthernet in decode-ethernet.c | Aug 28, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-10055HIGH An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file. | Aug 28, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-10054HIGH An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crash | Aug 28, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-10051HIGH An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs | Aug 28, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Suricata Ids.
Media articles that mention a CVE ID that affects a product developed by Suricata Ids — matched by CVE ID, not by vendor name.