Junglewise Threat Intelligence

CVE-2020-3259: Cisco ASA and FTD Information Disclosure Vulnerability

CVE-2020-3259 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-02-15

Technologies: Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD), Cisco Adaptive Security Appliance (ASA) Software. Vendors: Cisco.

Executive brief

A vulnerability in the web services interface of Cisco ASA and FTD software allows an unauthenticated, remote attacker to retrieve memory contents. This is caused by a buffer tracking issue when parsing invalid URLs, potentially leading to the disclosure of confidential information in specific AnyConnect and WebVPN configurations.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software 9.8 to 9.8.4.20, 9.9 to 9.9.2.67, 9.10 to 9.10.1.40, 9.12 to 9.12.3.9, 9.13 to 9.13.1.10
  • Cisco Firepower Threat Defense (FTD) Software

Timeline

  • 2020-05-06: disclosed: Original Cisco advisory date (implied by CVE year and NVD analysis)
  • 2024-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-02-15: exploited: Confirmed as exploited in the wild by CISA

Related threats