CVE-2020-3580
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), fix it now.
CISA required action: Apply updates per vendor instructions.
US federal civilian agencies must remediate by May 3, 2022.
Patch status
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: NVD patch reference
Description
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Affected products
| Product | Vendor | Source |
|---|---|---|
| Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco | KEV |
Sources: KEV = CISA Known Exploited Vulnerabilities catalog. Version details have not been published yet.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdateKEV
CVE-2020-3580 scored CVSS 6.1: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) systems are exposed to active attacks now.
Basis: NIST National Vulnerability Database
- Patch releasedUpdateKEV
Patch released for CVE-2020-3580: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
An official fix is now available for Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD). This vulnerability is being exploited, so apply it promptly.
Basis: NVD patch reference
1 earlier event is available with a subscription. See plans.
Coverage
We have not published a story about this vulnerability yet.
