First published: Wed Oct 21 2020(Updated: )
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Threat Defense | <6.3.0.6 | |
Cisco Firepower Threat Defense | >=6.4.0<6.4.0.10 | |
Cisco Firepower Threat Defense | >=6.5.0<6.5.0.5 | |
Cisco Firepower Threat Defense | >=6.6.0<6.6.1 | |
Cisco Adaptive Security Appliance Software | >=9.7<9.8.4.29 | |
Cisco Adaptive Security Appliance Software | >=9.9<9.9.2.80 | |
Cisco Adaptive Security Appliance Software | >=9.10<9.10.1.44 | |
Cisco Adaptive Security Appliance Software | >=9.12<9.12.4.4 | |
Cisco Adaptive Security Appliance Software | >=9.13<9.13.1.13 | |
Cisco Adaptive Security Appliance Software | >=9.14<9.14.1.30 | |
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | ||
Cisco Firepower Threat Defense | <6.4.0.12 | |
Cisco Firepower Threat Defense | >=6.5.0<6.6.4 | |
Cisco Firepower Threat Defense | >=6.7.0<6.7.0.2 | |
Cisco Adaptive Security Appliance Software | <9.8.4.34 | |
Cisco Adaptive Security Appliance Software | >=9.9<9.9.2.85 | |
Cisco Adaptive Security Appliance Software | >=9.10<9.12.4.13 | |
Cisco Adaptive Security Appliance Software | >=9.13<9.13.1.21 | |
Cisco Adaptive Security Appliance Software | >=9.14<9.14.2.8 | |
Cisco Adaptive Security Appliance Software | >=9.15<9.15.1.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3580 is a vulnerability in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software that allows an unauthenticated attacker to conduct cross-site scripting (XSS) attacks.
The severity of CVE-2020-3580 is medium with a CVSS score of 6.1.
Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software versions 6.3.0.6 to 6.6.1, and 9.7 to 9.14.1.30 are affected by CVE-2020-3580.
An attacker can exploit CVE-2020-3580 by enticing a user to click on a specially crafted link or visit a web page containing malicious content.
Yes, Cisco has released software updates to address CVE-2020-3580. It is recommended to update to the fixed software versions.