Junglewise Threat Intelligence

CVE-2020-3580: Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

CVE-2020-3580 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2021-11-03

Technologies: Cisco Adaptive Security Appliance (ASA), Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD). Vendors: Cisco.

Executive brief

Cisco ASA and FTD Software contain multiple cross-site scripting (XSS) vulnerabilities in their web services interface due to insufficient input validation. An unauthenticated remote attacker can exploit these by persuading a user to click a crafted link, allowing the execution of arbitrary script code or access to sensitive browser information.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software 9.7 to 9.8.4.34, 9.9 to 9.9.2.85, 9.10 to 9.12.4.13, 9.13 to 9.13.1.21, 9.14 to 9.14.2.8, 9.15 to 9.15.1.15
  • Cisco Firepower Threat Defense (FTD) Software Up to 6.4.0.12, 6.5.0 to 6.6.4, 6.7.0 to 6.7.0.2

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed
  • 2021-11-03: exploited: Reported as exploited in the wild.

Related threats