Executive brief
A vulnerability in the web services interface of Cisco ASA and FTD software allows an unauthenticated, remote attacker to retrieve memory contents. This is caused by a buffer tracking issue when parsing invalid URLs, potentially leading to the disclosure of confidential information in specific AnyConnect and WebVPN configurations.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software 9.8 to 9.8.4.20, 9.9 to 9.9.2.67, 9.10 to 9.10.1.40, 9.12 to 9.12.3.9, 9.13 to 9.13.1.10
- Cisco Firepower Threat Defense (FTD) Software
Timeline
- 2020-05-06: disclosed: Original Cisco advisory date (implied by CVE year and NVD analysis)
- 2024-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-02-15: exploited: Confirmed as exploited in the wild by CISA