CVE-2020-3580
medium · 6.1Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | secure_firewall_threat_defense | < 6.4.0.12 |
| cisco | secure_firewall_threat_defense | >= 6.5.0, < 6.6.4 |
| cisco | secure_firewall_threat_defense | >= 6.7.0, < 6.7.0.2 |
| cisco | adaptive_security_appliance_software | < 9.8.4.34 |
| cisco | adaptive_security_appliance_software | >= 9.9, < 9.9.2.85 |
| cisco | adaptive_security_appliance_software | >= 9.10, < 9.12.4.13 |
| cisco | adaptive_security_appliance_software | >= 9.13, < 9.13.1.21 |
| cisco | adaptive_security_appliance_software | >= 9.14, < 9.14.2.8 |
| cisco | adaptive_security_appliance_software | >= 9.15, < 9.15.1.15 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-3580