Skip to content
COOEY

EXPOSURES › CVE-2020-3580

CVE-2020-3580

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3580 ↗
⌖ EXPLOITED IN THE WILD SHAME 68/100 ransomwareexploited-in-wildunpatched

Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks.

A flaw in Cisco ASA/FTD web services allowed attackers to execute cross-site scripting, potentially stealing browser data and compromising the device. DIB organizations using these devices must immediately patch to prevent exploitation, as this vulnerability was actively exploited and linked to ransomware campaigns, impacting CMMC compliance.

Shame score — A widely-used security device had a preventable XSS vulnerability exploited in the wild, demonstrating a failure in secure coding practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Significant concerns raised regarding Cisco's security practices due to the vulnerability and subsequent breach.
dailysecurityreview.com ↗ severe-fallout -0.90
Strongly negative, highlighting a data breach impacting Cisco's DevHub.
"Cisco confirms a breach of its public-facing DevHub, exposing source code, credentials, and API tokens..."
cooey ↗ severe-fallout -0.60
Neutral reporting of the vulnerability details.
"Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability..."
cvefeed.io ↗ severe-fallout -0.30
Negative, emphasizing the significance of the KEV catalog and potential for exploitation.
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal..."
cve.akaoma.com ↗ severe-fallout -0.20
Negative, highlighting the importance of real-time vulnerability tracking.
"Cyber threats are constantly evolving, making real-time vulnerability tracking essential."
xposedornot.com ↗ severe-fallout +0.00
Neutral listing of the CVE within a broader database.
www.cvefind.com ↗ severe-fallout +0.00
Neutral listing of the CVE within a broader database.
app.opencve.io ↗ severe-fallout +0.00
Neutral listing of the CVE within a broader database.
AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized