First published: Wed Oct 21 2020(Updated: )
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Threat Defense | <6.3.0.6 | |
Cisco Firepower Threat Defense | >=6.4.0<6.4.0.10 | |
Cisco Firepower Threat Defense | >=6.5.0<6.5.0.5 | |
Cisco Firepower Threat Defense | >=6.6.0<6.6.1 | |
Cisco Adaptive Security Appliance Software | <9.8.4.29 | |
Cisco Adaptive Security Appliance Software | >=9.9<9.9.2.80 | |
Cisco Adaptive Security Appliance Software | >=9.10<9.10.1.44 | |
Cisco Adaptive Security Appliance Software | >=9.12<9.12.4.4 | |
Cisco Adaptive Security Appliance Software | >=9.13<9.13.1.13 | |
Cisco Adaptive Security Appliance Software | >=9.14<9.14.1.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3581 is a vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software that allows an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks.
The severity of CVE-2020-3581 is medium with a CVSS score of 6.1.
Cisco Firepower Threat Defense versions 6.3.0.6 to 6.6.1 and Cisco Adaptive Security Appliance Software versions 9.8.4.29 to 9.14.1.30 are affected by CVE-2020-3581.
An attacker can exploit CVE-2020-3581 by conducting cross-site scripting (XSS) attacks against a user of the web services interface.
You can find more information about CVE-2020-3581 on the Cisco Security Advisory page: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-multiple-FCB3vPZe