TROYANOSYVIRUS
Volver a CVEs

CVE-2020-3259

HIGHCISA KEV
7.5

Descripcion

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

Detalles CVE

Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado5/6/2020
Ultima modificacion10/28/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorCisco
ProductoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Nombre vulnerabilidadCisco ASA and FTD Information Disclosure Vulnerability
Fecha inclusion KEV2024-02-15
Fecha limite remediacion2024-03-07
Uso en ransomwareKnown

Productos afectados

cisco:adaptive_security_appliance_softwarecisco:firepower_threat_defense

Debilidades (CWE)

CWE-200

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.