Cisco ASA and Cisco FTD - Cross-Site Scripting (CVE-2020-3580)
- Severity
- CVSSv3 Score
- 6.1
- Exploitable with Sniper
- No
- Vulnerability description
Cisco ASA device is affected by a Cross-Site Scripting (XSS) vulnerability in the /+CSCOE+/saml/sp/acs endpoint. The root cause of this vulnerability is the lack of validation in user-supplied input. An attacker can exploit this vulnerability to inject malicious JavaScript code in the URI.
- Risk description
The risk exists that a remote unauthenticated attacker could exploit this vulnerability by sending malicious URLs to Cisco ASA users and gaining access to sensitive, browser-based information.
- Recommendation
Applying the latest Cisco ASA patch will fix this vulnerability.
- References
- Detectable with
- Network Scanner
- Vuln date
- Oct 2020
- Published at
- Updated at
- Software Type
- VPN gateway
- Vendor
- Cisco
- Product
- Adaptive Security Appliance (ASA)
- Codename
- Not available