Information disclosure in Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software



Published: 2020-05-07 | Updated: 2024-02-01
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2020-3259
CWE-ID CWE-200
Exploitation vector Network
Public exploit Vulnerability #1 is being exploited in the wild.
Vulnerable software
Subscribe
Cisco Adaptive Security Appliance (ASA)
Hardware solutions / Security hardware applicances

Cisco Firepower Threat Defense (FTD)
Hardware solutions / Security hardware applicances

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU27595

Risk: High

CVSSv3.1: 7.2 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C]

CVE-ID: CVE-2020-3259

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. A remote attacker can send a specially crafted GET request and gain unauthorized access to sensitive information on the system.

Mitigation

Vendor recommends to update the Cisco FTD Software Release to version 6.2.3.16 (June 2020), 6.3.0.6 (future release), 6.4.0.9 (May 2020) and 6.5.0.5 (future release).

Vulnerable software versions

Cisco Adaptive Security Appliance (ASA): 9.5 - 9.13

Cisco Firepower Threat Defense (FTD): 6.2.3 - 6.5.0

External links

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMB
http://www.truesec.com/hub/blog/akira-ransomware-and-exploitation-of-cisco-anyconnect-vulnerability-cve-2020-3259


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

Yes. This vulnerability is being exploited in the wild.



###SIDEBAR###