CVE-2020-3259

Confirmed PUBLISHED

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

Cisco · Cisco Adaptive Security Appliance (ASA) Software
Exploited in the wild Used in malware

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High

At a Glance

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

edge malware nessus_scanner ransomware cisa
CVE Published
May 06, 2020
Exploitation Reported
Feb 15, 2024
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
cisco
firepower_threat_defense

6.2.3 to < 6.2.3.16

Affected
cisco
firepower_threat_defense

6.3.0 to < 6.3.0.6

Affected
cisco
firepower_threat_defense

6.4.0 to < 6.4.0.9

Affected
cisco
firepower_threat_defense

6.5.0 to < 6.5.0.5

Affected
cisco
adaptive_security_appliance_software

9.8 to < 9.8.4.20

Affected
cisco
adaptive_security_appliance_software

9.9 to < 9.9.2..67

Affected
cisco
adaptive_security_appliance_software

9.10 to < 9.10.1.40

Affected
cisco
adaptive_security_appliance_software

9.12 to < 9.12.3.9

Affected
cisco
adaptive_security_appliance_software

9.13 to < 9.13.1.10

Affected
Cisco
Cisco Adaptive Security Appliance (ASA) Software

n/a

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.