CVE-2020-3578
published 2020-10-21CVE-2020-3578: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…
PriorityP339medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.23%
65.7th percentile
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation of URLs when portal access rules are configured. An attacker could exploit this vulnerability by accessing certain URLs on the affected device.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | < 9.6.4.45 | 9.6.4.45 |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.44 | 9.10.1.44 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.4.4 | 9.12.4.4 |
| cisco | adaptive_security_appliance_software | >= 9.13 < 9.13.1.13 | 9.13.1.13 |
| cisco | adaptive_security_appliance_software | >= 9.14 < 9.14.1.19 | 9.14.1.19 |
| cisco | adaptive_security_appliance_software | >= 9.7 < 9.8.4.26 | 9.8.4.26 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.80 | 9.9.2.80 |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | firepower_threat_defense | < 6.3.0.6 | 6.3.0.6 |
| cisco | firepower_threat_defense | >= 6.4.0 < 6.4.0.10 | 6.4.0.10 |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.5.0.5 | 6.5.0.5 |
| cisco | firepower_threat_defense | >= 6.6.0 < 6.6.1 | 6.6.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
vendor_cisco·2020-10-21·CVSS 5.3
CVE-2020-3578 [MEDIUM] CWE-863 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
Update from October 22nd, 2020: Cisco has become aware of a new Cisco Adaptive Security Appliance vulnerability that could affect the fixed releases recommended for code trains 9.13 and 9.14 in the Fixed Software section of this advisory. See the Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability for additional information.
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked.
The vulne
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3578 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
CVE-2020-3578: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Portal Access Rule Bypass Vulnerability
Update from October 22nd, 2020 : Cisco has become aware of a new Cisco Adaptive Security Appliance vulnerability that could affect the fixed releases recommended for code trains 9.13 and 9.14 in the Fixed Software section of this advisory. See the Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability for additional information. A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be block
GHSA
GHSA-6rgf-4c44-8hwh: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
ghsa_unreviewed·2022-05-24
CVE-2020-3578 [MEDIUM] CWE-863 GHSA-6rgf-4c44-8hwh: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. The vulnerability is due to insufficient validation of URLs when portal access rules are configured. An attacker could exploit this vulnerability by accessing certain URLs on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-21
Published