CVE-2020-3580

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities

Basic Information

CVE State
PUBLISHED
Reserved Date
December 12, 2019
Published Date
October 21, 2020
Last Updated
November 08, 2024
Vendor
Cisco
Product
Cisco Adaptive Security Appliance (ASA) Software
Description
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

CVSS Scores

CVSS v3.1

6.1 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

SSVC Information

Exploitation
active
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2022-07-15 00:11:29 UTC) Source
Used in Malware
Yes (added 2021-11-03 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

catatonicprime/CVE-2020-3580

Type: github • Created: 2022-07-15 00:11:29 UTC • Stars: 2

Additional exploits for XSS in Cisco ASA devices discovered by PTSwarm

adarshvs/CVE-2020-3580

Type: github • Created: 2021-06-28 06:51:26 UTC • Stars: 21

Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.

Hudi233/CVE-2020-3580

Type: github • Created: 2021-06-25 04:39:30 UTC • Stars: 9