CVE-2020-3578: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation of URLs when portal access rules are configured. An attacker could exploit this vulnerability by accessing certain URLs on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3578?
CVE-2020-3578 is a vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.
How does CVE-2020-3578 work?
CVE-2020-3578 allows an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked.
Which software products are affected by CVE-2020-3578?
Cisco Adaptive Security Appliance (ASA) Software versions 9.6.4.45 to 9.14.1.19 and Cisco Firepower Threat Defense (FTD) Software versions 6.3.0.6 to 6.6.1 are affected by CVE-2020-3578.
What is the severity of CVE-2020-3578?
CVE-2020-3578 has a severity score of 6.5, which is considered medium.
How can I fix CVE-2020-3578?
Update to a fixed version of Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software as mentioned in the advisory provided by Cisco.