Cross-site scripting in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2024-20382
Published: October 24, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the VPN web client services feature. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2024-20382
Cisco Adaptive Security Appliance (ASA) - addressed in versions 7.0.6.3, 7.2.9, 7.4.2.1, 7.6.0, 9.16.4.62, 9.16.4.67, 9.16.4.70, 9.16.4.71, 9.17.1.45, 9.18.4.34, 9.18.4.40, 9.18.4.47, 9.19.1.37, 9.20.3, 9.20.3.4, 9.20.3.7, 9.22.1.1