cbcvebase.
CVE-2019-12695
published 2019-10-02

CVE-2019-12695: A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance< 9.6.4.319.6.4.31
ciscoadaptive_security_appliance_and_firepower_threat_defense
ciscoadaptive_security_appliance_software>= 9.10 < 9.10.1.309.10.1.30
ciscoadaptive_security_appliance_software>= 9.12 < 9.12.2.99.12.2.9
ciscoadaptive_security_appliance_software>= 9.13 < 9.13.19.13.1
ciscoadaptive_security_appliance_software>= 9.7 < 9.8.4.99.8.4.9
ciscoadaptive_security_appliance_software>= 9.9 < 9.9.2.569.9.2.56
ciscocisco_adaptive_security_appliance_software>= unspecified < n/an/a
ciscofirepower_threat_defense< 6.2.3.156.2.3.15
ciscofirepower_threat_defense>= 6.3.0 < 6.3.0.56.3.0.5
ciscofirepower_threat_defense>= 6.4.0 < 6.4.0.66.4.0.6