- Description
- Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sends multiple SYN packets with different sequence numbers within the same flow tuple, which can cause Suricata to fail to pick up the TCP session. In IDS mode this can lead to a detection and logging bypass. In IPS mode this will lead to the flow getting blocked. This issue is fixed in versions 7.0.12 and 8.0.1.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- suricata
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-358
- Hype score
- Not currently trending
CVE-2025-59147 TCP Session Detection Bypass Vulnerability in Suricata Versions 7.0.11 and 8.0.0 https://t.co/3O8qe3xODw
@VulmonFeeds
2 Oct 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Suricata TCP Detection Bypass Alert CVE-2025-59147 lets attackers evade Suricata’s IDS/IPS by exploiting a flaw in its TCP stream handling. Patch and review rules now. For more details, read ZeroPath's blog on this vuln. #NetworkSecurity #IDS #AppSec https://t.co/6Ruy5vfVcc
@ZeroPathLabs
1 Oct 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-59147 Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as w… https://t.co/e8Niyp2GaL
@CVEnew
1 Oct 2025
338 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CD9C7EA7-5925-4C2B-815B-13F87DDB3F9C",
"versionEndExcluding": "7.0.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oisf:suricata:8.0.0:-:*:*:*:*:*:*",
"matchCriteriaId": "016370F6-3404-4F20-ABED-C0D23AC7D1D2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oisf:suricata:8.0.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "2C51F6B1-2B23-4C24-9B69-DA71597628C6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oisf:suricata:8.0.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "722B8967-EC47-43AF-AB71-4F7487780CED",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]