CVE-2020-3583
21.10.2020, 19:15
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Vendor | Product | Version |
---|---|---|
cisco | firepower_threat_defense | 𝑥 < 6.3.0.6 |
cisco | firepower_threat_defense | 6.4.0 ≤ 𝑥 < 6.4.0.10 |
cisco | firepower_threat_defense | 6.5.0 ≤ 𝑥 < 6.5.0.5 |
cisco | firepower_threat_defense | 6.6.0 ≤ 𝑥 < 6.6.1 |
cisco | adaptive_security_appliance_software | 9.7 ≤ 𝑥 < 9.8.4.29 |
cisco | adaptive_security_appliance_software | 9.9 ≤ 𝑥 < 9.9.2.80 |
cisco | adaptive_security_appliance_software | 9.10 ≤ 𝑥 < 9.10.1.44 |
cisco | adaptive_security_appliance_software | 9.12 ≤ 𝑥 < 9.12.4.4 |
cisco | adaptive_security_appliance_software | 9.13 ≤ 𝑥 < 9.13.1.13 |
cisco | adaptive_security_appliance_software | 9.14 ≤ 𝑥 < 9.14.1.30 |
𝑥
= Vulnerable software versions