CVE-2020-3580
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 12, 2019
- Published Date
- October 21, 2020
- Last Updated
- November 08, 2024
- Vendor
- Cisco
- Product
- Cisco Adaptive Security Appliance (ASA) Software
- Description
- Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
CVSS Scores
CVSS v3.1
6.1 - MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
SSVC Information
- Exploitation
- active
- Technical Impact
- partial
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-3580.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
catatonicprime/CVE-2020-3580
Type: github • Created: 2022-07-15 00:11:29 UTC • Stars: 2
Additional exploits for XSS in Cisco ASA devices discovered by PTSwarm
adarshvs/CVE-2020-3580
Type: github • Created: 2021-06-28 06:51:26 UTC • Stars: 21
Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.
Hudi233/CVE-2020-3580
Type: github • Created: 2021-06-25 04:39:30 UTC • Stars: 9