CVE-2020-3580(cisco / adaptive_security_appliance_software)

LOWCVSS 6.1 ยท MEDIUMCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance_software
  • secure_firewall_threat_defense

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
adaptive_security_appliance_softwaresecure_firewall_threat_defense

Deep dive

Activity timeline1 mentions / 1d
00111Mentions ยท 2026-09-25: 109-25
Full discourse1 post
  • General Intels Daily@intels_daily

    ๐Ÿ”ด ๐—–๐—ฅ๐—œ๐—ง๐—œ๐—–๐—”๐—Ÿ ยท ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜€๐—ฎ๐—น๐—ฒ ๐Ÿข Target: ๐—ก๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—œ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐—ถ๐—ฎ๐—น ๐——๐—ฒ๐˜ƒ๐—ฒ๐—น๐—ผ๐—ฝ๐—บ๐—ฒ๐—ป๐˜ ๐—–๐—ฒ๐—ป๐˜๐—ฒ๐—ฟ ๐Ÿงฉ Products: ๐—–๐—ถ๐˜€๐—ฐ๐—ผ ๐—œ๐—ข๐—ฆ ๐—ซ๐—˜, ๐—–๐—ถ๐˜€๐—ฐ๐—ผ ๐—–๐—ฎ๐˜๐—ฎ๐—น๐˜†๐˜€๐˜ ๐Ÿต๐Ÿฐ๐Ÿฌ๐Ÿณ, ๐—–๐—ถ๐˜€๐—ฐ๐—ผ ๐—–๐—ฎ๐˜๐—ฎ๐—น๐˜†๐˜€๐˜ ๐Ÿต๐Ÿฏ๐Ÿฌ๐Ÿฌ ๐Ÿ›ก๏ธ CVE-2016-6366, CVE-2020-3580 Threat actor Blacknet00 claims to have compromised the National Industrial Development Center (NIDC) in Saudi Arabia. The post provides detailed technical artifacts, including network device configurations, internal IP addresses, routing tables, and multiple backdoor credentials for a Cisco router (NIDC-DC-RTR-MOBILY). #AccessSale #InitialAccess #ThreatIntel #CTI

    00010163
    659 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoadaptive_security_appliance_software---
Appciscosecure_firewall_threat_defense---

Explore more