CVE-2020-3259
published 2020-05-06CVE-2020-3259: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…
PriorityP189high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-03-07
Exploited in the wild
EPSS
71.79%
99.4th percentile
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.40 | 9.10.1.40 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.3.9 | 9.12.3.9 |
| cisco | adaptive_security_appliance_software | >= 9.13 < 9.13.1.10 | 9.13.1.10 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.4.20 | 9.8.4.20 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.67 | 9.9.2.67 |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | firepower_threat_defense | >= 6.2.3 < 6.2.3.16 | 6.2.3.16 |
| cisco | firepower_threat_defense | >= 6.3.0 < 6.3.0.6 | 6.3.0.6 |
| cisco | firepower_threat_defense | >= 6.4.0 < 6.4.0.9 | 6.4.0.9 |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.5.0.5 | 6.5.0.5 |
Detection & IOCsextracted from sources · hover to see the quote
command"C:\Program Files\WinRAR\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . "[REDACTED]\Company\[REDACTED]" [REDACTED]\Company\HR "[REDACTED]\Company\Human Resources Management - HR"↗
- →Monitor for crafted GET requests to the Cisco ASA/FTD web services interface with invalid/malformed URLs, which is the exploitation mechanism for CVE-2020-3259. ↗
- →CVE-2020-3259 is actively exploited by the Akira ransomware group (Howling Scorpius) for initial access; treat any unpatched Cisco ASA/FTD with AnyConnect or WebVPN enabled as high-priority targets. ↗
- →Detect Akira post-exploitation persistence by alerting on creation of new administrative domain accounts named 'itadm'. ↗
- →Detect Akira credential dumping via comsvcs.dll MiniDump of the LSASS process. ↗
- →Alert on use of the Zemana antimalware driver being loaded by non-Zemana processes, as Akira affiliates abuse it to terminate antimalware-related processes. ↗
- →Monitor for unauthorized HTTPS request patterns against Cisco ASA/FTD web services interfaces and flag retrieval of unexpected or sensitive data from ASA or FTD devices. ↗
- ·CVE-2020-3259 only affects Cisco ASA/FTD devices with specific AnyConnect or WebVPN configurations enabled; devices without these features are not vulnerable. ↗
- ·The vulnerability is rooted in a buffer tracking issue when parsing invalid URLs on the web services interface; the attack surface is the externally accessible HTTPS web services module. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vw99-pf8w-g3cw: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
ghsa_unreviewed·2022-05-24
CVE-2020-3259 [MEDIUM] CWE-200 GHSA-vw99-pf8w-g3cw: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more infor
VulnCheck
Cisco ASA and FTD Information Disclosure Vulnerability
vulncheck·2020·CVSS 7.5
CVE-2020-3259 [HIGH] CWE-200 Cisco ASA and FTD Information Disclosure Vulnerability
Cisco ASA and FTD Information Disclosure Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.tru
CISA
Cisco ASA and FTD Information Disclosure Vulnerability
cisa·2024-02-15·CVSS 7.5
CVE-2020-3259 [HIGH] CWE-200 Cisco ASA and FTD Information Disclosure Vulnerability
Vulnerability: Cisco ASA and FTD Information Disclosure Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://tools.cisco.com/security/center/content/CiscoSecu
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
vendor_cisco·2020-05-06·CVSS 7.5
CVE-2020-3259 [HIGH] CWE-200 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information.
The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclo
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3259 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
CVE-2020-3259: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead
Suricata
ET WEB_SPECIFIC_APPS Cisco ASA/FTD Memory Leak Attempt (CVE-2020-3259)
suricata·2025-03-07·CVSS 7.5
CVE-2020-3259 [HIGH] ET WEB_SPECIFIC_APPS Cisco ASA/FTD Memory Leak Attempt (CVE-2020-3259)
ET WEB_SPECIFIC_APPS Cisco ASA/FTD Memory Leak Attempt (CVE-2020-3259)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco ASA/FTD Memory Leak Attempt (CVE-2020-3259)"; flow:established,to_server; http.method; content:"GET"; http.uri; bsize:>800; content:"|2b|CSCOE|2b|/sdesktop/webstart.xml|3f|"; fast_pattern; content:"|25|p"; endswith; reference:url,github.com/GossiTheDog/Exploits/blob/main/Cisco-CVE-2020-3259.sh; reference:cve,2020-3259; classtype:attempted-admin; sid:2060671; rev:1; metadata:affected_product Cisco_ASA, attack_target Networking_Equipment, tls_state TLSDecrypt, created_at 2025_03_07, cve CVE_2020_3259, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Descrip
No public exploits indexed.
Greynoiseio
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
blogs_greynoiseio·2025-09-04
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Unit42
Threat Assessment: Howling Scorpius (Akira Ransomware)
blogs_unit42·2024-12-02·CVSS 7.5
CVE-2020-3259 [HIGH] Threat Assessment: Howling Scorpius (Akira Ransomware)
## Threat Assessment: Howling Scorpius (Akira Ransomware)
Yoav Zemah
Published: December 2, 2024
Cybercrime
High Profile Threats
Ransomware
Akira ransomware
Bring Your Own Driver
CVE-2020-3259
CVE-2023-20269
Double extortion
ESXi
FTP
Howling Scorpius
Lazagne
Leak site
Linux
Megazord
Mimikatz
Remote desktop
Rust
Server Message Block
Torrenting
Windows
## Executive Summary
Emerging in early 2023, the Howling Scorpius ransomware group is the entity behind the Akira ransomware-as-a-service (RaaS), which has consistently ranked in recent months among the top five most active ransomware groups. Its double extortion strategy significantly amplifies the threat it poses. Unit 42 researchers have been monitoring the Howling Scorpius ransomware group over the past year.
H
Unit42
Threat Assessment: Howling Scorpius (Akira Ransomware)
blogs_unit42·2024-12-02
Threat Assessment: Howling Scorpius (Akira Ransomware)
## Executive Summary
Emerging in early 2023, the Howling Scorpius ransomware group is the entity behind the Akira ransomware-as-a-service (RaaS), which has consistently ranked in recent months among the top five most active ransomware groups. Its double extortion strategy significantly amplifies the threat it poses. Unit 42 researchers have been monitoring the Howling Scorpius ransomware group over the past year.
Howling Scorpius targets small to medium-sized businesses in North America, Europe and Australia, across various sectors. Affected industries include education, consulting, government, manufacturing, telecommunications, technology and pharmaceuticals.
Our research reveals that Howling Scorpius maintains and operates encryptors for Windows and Linux operating systems. We identif
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
## Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to mo
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to moderate confidence that this shift was due
Talos
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
blogs_talos·2024-07-25
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
## IR Trends: Ransomware on the rise, while technology becomes most targeted sector
Business email compromise (BEC) and ransomware were the top threats observed by Cisco Talos Incident Response (Talos IR) in the second quarter of 2024, together accounting for 60 percent of engagements.
Although there was a decrease in BEC engagements from last quarter , it was still a major threat for the second quarter in a row. There was a slight increase in ransomware where Talos IR responded to Mallox and Underground Team ransomware for the first time this quarter, as well as the previously seen Black Basta and BlackSuit ransomware operations.
For the third quarter in a row, the most observed means of gaining initial access was the use of compromised credentials on valid accounts, which accounted fo
Talos
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
blogs_talos·2024-07-25
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
Business email compromise (BEC) and ransomware were the top threats observed by Cisco Talos Incident Response (Talos IR) in the second quarter of 2024, together accounting for 60 percent of engagements.
Although there was a decrease in BEC engagements from last quarter, it was still a major threat for the second quarter in a row. There was a slight increase in ransomware where Talos IR responded to Mallox and Underground Team ransomware for the first time this quarter, as well as the previously seen Black Basta and BlackSuit ransomware operations.
For the third quarter in a row, the most observed means of gaining initial access was the use of compromised credentials on valid accounts, which accounted for 60 percent of engagements this quarter, a 25 percent increase from the previous quar
Zscaler
Another CVE (PAN-OS Zero Day) | Zscaler
blogs_zscaler·2024-04-12·CVSS 10.0
[CRITICAL] Another CVE (PAN-OS Zero Day) | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bleepingcomputer
The Week in Ransomware - February 2nd 2024 - No honor among thieves
blogs_bleepingcomputer·2024-02-02
The Week in Ransomware - February 2nd 2024 - No honor among thieves
## The Week in Ransomware - February 2nd 2024 - No honor among thieves
## Lawrence Abrams
Attacks on hospitals continued this week, with ransomware operations disrupting patient care as they force organization to respond to cyberattacks.
While many, like LockBit, claim to have policies in place to avoid encryping hospitals, we continue to see affiliates targeting healthcare with complete disregard to the disruption they are causing patients in trying to receive care.
LockBit says that affiliates can only steal data and not encrypt hospitals, yet they purposely ignore the fact that attacking an organization will cause them to turn off IT system to prevent the spread of the attack.
For hospitals, this means that they no longer have access to medical charts, can't prescribe electronic pr
Tenable
Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
blogs_tenable·2020-05-07·CVSS 9.1
[CRITICAL] Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
CVE-2020-3259 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 7.5
CVE-2020-3259 [HIGH] CVE-2020-3259 Vulnerability: Analysis, Impact, Mitigation | Huntress
## CVE-2020-3259 Vulnerability
Published: 11/21/2025
Written by: Lizzie Danielson
## What is CVE-2020-3259 vulnerability?
CVE-2020-3259 is a vulnerability in the Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software, classified as an information disclosure issue. It allows attackers to exploit improperly configured interfaces to gain unauthorized access to sensitive data. This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 7.5, making it a high-severity threat. It directly impacts the confidentiality of affected systems by enabling attackers to retrieve system files.
## When was it discovered?
CVE-2020-3259 was disclosed publicly on September 9, 2020. The vulnerability was identified and patched by Cisco’s Product Security Incide
Greynoiseio
NoiseLetter March 2024
blogs_greynoiseio
NoiseLetter March 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMBhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMBhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3259
2020-05-06
Published
2024-02-15
Added to CISA KEV
Exploited in the wild