HomePentest-Tools.com Logo

Cisco ASA and Cisco FTD - Cross-Site Scripting (CVE-2020-3580)

Severity
CVSSv3 Score
6.1
Exploitable with Sniper
No
Vulnerability description

Cisco ASA device is affected by a Cross-Site Scripting (XSS) vulnerability in the /+CSCOE+/saml/sp/acs endpoint. The root cause of this vulnerability is the lack of validation in user-supplied input. An attacker can exploit this vulnerability to inject malicious JavaScript code in the URI.

Risk description

The risk exists that a remote unauthenticated attacker could exploit this vulnerability by sending malicious URLs to Cisco ASA users and gaining access to sensitive, browser-based information.

Recommendation

Applying the latest Cisco ASA patch will fix this vulnerability.

Detectable with
Network Scanner
Vuln date
Oct 2020
Published at
Updated at
Software Type
VPN gateway
Vendor
Cisco
Product
Adaptive Security Appliance (ASA)
Codename
Not available