CVE-2025-59147
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sends multiple SYN packets with different sequence numbers within the same flow tuple, which can cause Suricata to fail to pick up the TCP session. In IDS mode this can lead to a detection and logging bypass. In IPS mode this will lead to the flow getting blocked. This issue is fixed in versions 7.0.12 and 8.0.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1211Exploitation for Stealthstealth80 %
Suricata expone servicio de inspección de red a la red sin autenticación (AV:N, PR:N, UI:N); la evasión de detección mediante tráfico crafted es evasión de defensas (T1211). Integridad alta (I:H) refleja bypass de seguridad, no modificación de datos del usuario.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-358
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-59147",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-59147",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-10-01T19:42:12.196265Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "OISF",
"product": "suricata",
"versions": [
{
"status": "affected",
"version": "< 7.0.12"
},
{
"status": "affected",
"version": ">= 8.0.0, < 8.0.1"
}
]
}
]
}
],
"published": "2025-10-01T20:18:38.267",
"references": [
{
"url": "https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OISF/suricata/commit/be6315dba0d9101b11d16e9dacfe2822b3792f1b",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OISF/suricata/commit/e91b03c90385db15e21cf1a0e85b921bf92b039e",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/OISF/suricata/security/advisories/GHSA-v8hv-6v7x-4c2r",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-358"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sends multiple SYN packets with different sequence numbers within the same flow tuple, which can cause Suricata to fail to pick up the TCP session. In IDS mode this can lead to a detection and logging bypass. In IPS mode this will lead to the flow getting blocked. This issue is fixed in versions 7.0.12 and 8.0.1."
},
{
"lang": "es",
"value": "Suricata es un motor IDS, IPS y NSM de red desarrollado por la OISF (Open Information Security Foundation) y la comunidad Suricata. Las versiones 7.0.11 e inferiores, así como la 8.0.0, son vulnerables a una omisión de detección cuando tráfico manipulado envía múltiples paquetes SYN con diferentes números de secuencia dentro de la misma tupla de flujo, lo que puede causar que Suricata no logre detectar la sesión TCP. En modo IDS esto puede llevar a una omisión de detección y registro. En modo IPS esto hará que el flujo sea bloqueado. Este problema está solucionado en las versiones 7.0.12 y 8.0.1."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD9C7EA7-5925-4C2B-815B-13F87DDB3F9C",
"versionEndExcluding": "7.0.12"
},
{
"criteria": "cpe:2.3:a:oisf:suricata:8.0.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "016370F6-3404-4F20-ABED-C0D23AC7D1D2"
},
{
"criteria": "cpe:2.3:a:oisf:suricata:8.0.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C51F6B1-2B23-4C24-9B69-DA71597628C6"
},
{
"criteria": "cpe:2.3:a:oisf:suricata:8.0.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "722B8967-EC47-43AF-AB71-4F7487780CED"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}