CVE-2020-3580 is a cross-site scripting (XSS) vulnerability in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, specifically impacting AnyConnect and WebVPN configurations. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated, remote attacker to execute arbitrary script code or access sensitive browser-based information by tricking a user into clicking a crafted link. It is actively exploited in the wild, including by the Akira ransomware group, and has garnered significant community attention and media coverage, despite no public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.0.12CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.5.0, < 6.6.4CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.7.0, < 6.7.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
< 9.8.4.34CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.9, < 9.9.2.85CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.