EXPOSURES › CVE-2020-3580
CVE-2020-3580
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks.
A flaw in Cisco ASA/FTD web services allowed attackers to execute cross-site scripting, potentially stealing browser data and compromising the device. DIB organizations using these devices must immediately patch to prevent exploitation, as this vulnerability was actively exploited and linked to ransomware campaigns, impacting CMMC compliance.
Shame score — A widely-used security device had a preventable XSS vulnerability exploited in the wild, demonstrating a failure in secure coding practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
"Cisco confirms a breach of its public-facing DevHub, exposing source code, credentials, and API tokens..."
"Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability..."
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal..."
"Cyber threats are constantly evolving, making real-time vulnerability tracking essential."
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |