CVE-2020-3580
published 2020-10-21CVE-2020-3580: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software…
PriorityP184medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
85.44%
99.7th percentile
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | < 9.8.4.34 | 9.8.4.34 |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.12.4.13 | 9.12.4.13 |
| cisco | adaptive_security_appliance_software | >= 9.13 < 9.13.1.21 | 9.13.1.21 |
| cisco | adaptive_security_appliance_software | >= 9.14 < 9.14.2.8 | 9.14.2.8 |
| cisco | adaptive_security_appliance_software | >= 9.15 < 9.15.1.15 | 9.15.1.15 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.85 | 9.9.2.85 |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | firepower_threat_defense | < 6.4.0.12 | 6.4.0.12 |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.6.4 | 6.6.4 |
| cisco | firepower_threat_defense | >= 6.7.0 < 6.7.0.2 | 6.7.0.2 |
Detection & IOCsextracted from sources · hover to see the quote
url/+CSCOE+/saml/sp/acs?tgname=a
otherSAMLResponse=%22%3E%3Csvg/onload=alert(/{{randstr}}/)%3E
snort↗
SID 57856
snort↗
SID 57857
- →The exploit targets the SAML ACS endpoint on Cisco ASA/FTD. Monitor for POST requests to /+CSCOE+/saml/sp/acs with a SAMLResponse parameter containing XSS payloads (e.g., SVG onload handlers or angle-bracket injections).
- →Vulnerability is only exploitable on devices with specific AnyConnect IKEv2 (with client services), AnyConnect SSL VPN, or Clientless SSL VPN (WebVPN) configurations enabled. Audit devices for these configurations as a triage step. ↗
- →CVE-2020-3580 is being actively exploited in the wild following public PoC release by Positive Technologies on June 24, 2021. Treat any unpatched ASA/FTD with WebVPN or AnyConnect exposed to the internet as high priority. ↗
- →HTTP response for a successful XSS probe will return status 200 with Content-Type: text/html and reflect the injected payload in the body. Use this as a detection matcher in web application scanners or proxies.
- ·The vulnerability only affects devices with AnyConnect IKEv2 Remote Access (with client services), AnyConnect SSL VPN, or Clientless SSL VPN (WebVPN) explicitly enabled. Devices without these configurations are not affected. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
vulncheck6.1MEDIUM
cisa6.1MEDIUM
vendor_cisco6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
cisa·2021-11-03·CVSS 6.1
CVE-2020-3580 [MEDIUM] CWE-79 Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Vulnerability: Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-3580
Remediation Due Date: 2022-05-03
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·2020-10-21·CVSS 6.1
CVE-2020-3580 [MEDIUM] CWE-79 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021: Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited.
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device.
The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuadi
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3581 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3581: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3582 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3582: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3583 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3583: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3580 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3580: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
GHSA
GHSA-rr9h-g433-576p: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So
ghsa_unreviewed·2022-05-24
CVE-2020-3580 [MEDIUM] CWE-79 GHSA-rr9h-g433-576p: Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnec
VulnCheck
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
vulncheck·2020·CVSS 6.1
CVE-2020-3580 [MEDIUM] CWE-79 Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-11-15&host_type
Suricata
ET EXPLOIT Cisco ASA XSS Attempt (CVE-2020-3580)
suricata·2021-09-21·CVSS 6.1
CVE-2020-3580 [MEDIUM] ET EXPLOIT Cisco ASA XSS Attempt (CVE-2020-3580)
ET EXPLOIT Cisco ASA XSS Attempt (CVE-2020-3580)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco ASA XSS Attempt (CVE-2020-3580)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/+CSCOE+/saml/sp/acs?tgname="; fast_pattern; http.request_body; content:"=|22|><"; reference:url,twitter.com/ptswarm/status/1408050644460650502; reference:cve,2020-3580; classtype:web-application-attack; sid:2033994; rev:2; metadata:affected_product Web_Server_Applications, attack_target Networking_Equipment, created_at 2021_09_21, cve CVE_2020_3580, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_09_21;)
Nuclei
Cisco ASA/FTD Software - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2020-3580 [MEDIUM] Cisco ASA/FTD Software - Cross-Site Scripting
Cisco ASA/FTD Software - Cross-Site Scripting
Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software are vulnerable to cross-site scripting and could allow an unauthenticated, remote attacker to conduct attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyC
Unit42
Network Security Trends: May-July 2021
blogs_unit42·2021-09-17
Network Security Trends: May-July 2021
## Executive Summary
Unit 42 researchers continue to observe network security trends, tracking how cybercriminals take advantage of vulnerabilities in the real world. The following sections present our analysis of the most recently published vulnerabilities, including their severity and category distribution. Additionally, we provide insight into how the vulnerabilities are exploited in the wild based on real-world data collected from Palo Alto Networks Next-Generation Firewalls. We highlight vulnerabilities ranked medium severity and above that were newly published from May-July 2021 in order to raise awareness of their active exploits in the wild. We then draw conclusions about the most commonly exploited vulnerabilities we observed attackers using, as well as the severity, category and
Unit42
Network Security Trends: May-July 2021
blogs_unit42·2021-09-17
Network Security Trends: May-July 2021
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: May-July 2021
Yue Guan
Lei Xu
Published: September 17, 2021
Malware
Trend Reports
Vulnerabilities
Attack analysis
Exploit
Exploit in the wild
Network security trends
## Executive Summary
Unit 42 researchers continue to observe network security trends, tracking how cybercriminals take advantage of vulnerabilities in the real world. The following sections present our analysis of the most recently published vulnerabilities, including their severity and category distribution. Additionally, we provide insight into how the vulnerabilities are exploited in the wild based on real-world data collected from Palo Alto Networks Next-Generation Firewalls . We highlight vulnerabilities ranked medium sever
Talos
Threat Source newsletter (July 1, 2021)
blogs_talos·2021-07-01
Threat Source newsletter (July 1, 2021)
## Threat Source newsletter (July 1, 2021)
Good afternoon, Talos readers.
There's been a lot of talk recently around how to address America's infrastructure cybersecurity. After attacks like Colonial Pipeline and JBS, everyone across the public and private sectors are wondering what they should be doing to avoid becoming the next major ransomware victim that disrupts their given industry.
While we don't have all the answers, our critical infrastructure experts recently suggested what some security partnerships could look like in the U.S. One of the authors of that post, Joe Marshall, joined the Talos Takes podcast last week with yours truly to discuss CI security and how operational technology can so often intersect with information technology.
## Upcoming Talos public engagements
Cha
Talos
Threat Source newsletter (July 1, 2021)
blogs_talos·2021-07-01
Threat Source newsletter (July 1, 2021)
Good afternoon, Talos readers.
There's been a lot of talk recently around how to address America's infrastructure cybersecurity. After attacks like Colonial Pipeline and JBS, everyone across the public and private sectors are wondering what they should be doing to avoid becoming the next major ransomware victim that disrupts their given industry.
While we don't have all the answers, our critical infrastructure experts recently suggested what some security partnerships could look like in the U.S. One of the authors of that post, Joe Marshall, joined the Talos Takes podcast last week with yours truly to discuss CI security and how operational technology can so often intersect with information technology.
## Upcoming Talos public engagements
Chats, Cheats, and Cracks: Abuse of Collaborati
Tenable
CVE-2020-3580: Proof of Concept Published for Cisco ASA Flaw Patched in October
blogs_tenable·2021-06-24·CVSS 6.1
[MEDIUM] CVE-2020-3580: Proof of Concept Published for Cisco ASA Flaw Patched in October
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
HackerOne
Reflected Cross Site Scripting Cisco ASA on myvpn.mtncameroon.net CVE-2020-3580
hackerone·2024-08-23·CVSS 6.1
CVE-2020-3580 [MEDIUM] Reflected Cross Site Scripting Cisco ASA on myvpn.mtncameroon.net CVE-2020-3580
Reflected Cross Site Scripting Cisco ASA on myvpn.mtncameroon.net CVE-2020-3580
##Summary:
Hello, I would like report this vulnerability to MTN, Cross Site Scripting on Cisco ASA CVE-2020-3580.
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device.
##Steps To Reproduce:
###how we can reproduce the issue;
1.Go to https://myvpn.mtncameroon.net ;
2. Intercept request with burp suite and send this "POST" Request, we will see response with JavaScript ..
* Request
```
POST /+CSCOE+/saml/sp/acs?tgname=a HTTP/1.1
Host: myvpn.mtncame
HackerOne
reflected xss [CVE-2020-3580]
hackerone·2024-05-03·CVSS 6.1
CVE-2020-3580 [MEDIUM] reflected xss [CVE-2020-3580]
reflected xss [CVE-2020-3580]
Hey Security Team
It was observed that the application is vulnerable to cross-site scripting (XSS). XSS is a type of attack that involves running a malicious scripts on a victim’s browser.
website: ███████ attached
When the user clicks submit, his information will be stolen
## Impact
Cookie Stealing - A malicious user can steal cookies and use them to gain access to the application.
Arbitrary requests - An attacker can use XSS to send requests that appear to be from the victim to the web server.
Malware download - XSS can prompt the user to download malware. Since the prompt looks like a legitimate request from the
site, the user may be more likely to trust the request and actually install the malware.
Defacement - attacker can deface the website usig javas
HackerOne
XSS DUE TO CVE-2020-3580
hackerone·2022-09-06·CVSS 6.1
CVE-2020-3580 [MEDIUM] XSS DUE TO CVE-2020-3580
XSS DUE TO CVE-2020-3580
Hello Team,
During my research, I found multiple hosts to be vulnerable to Cisco ASA XSS CVE-2020-3580, This vulnerability targets the saml service within the VPN. It is triggered via a POST request to domain/+CSCOE+/saml/sp/acs?tgname=a
## References
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-multiple-FCB3vPZe
## Impact
With this vulnerability, an attacker can for example steal users cookies or redirect users on malicious website.
## System Host(s)
█████
## Affected Product(s) and Version(s)
Cisco ASA
## CVE Numbers
CVE-2020-3580
## Steps to Reproduce
history.pushState('', '', '/')
document.forms[0].submit();
## Suggested Mitigation/Remediation Actions
Patch Cisco ASA : https://tools.cisco.com/secu
HackerOne
███████ - XSS - CVE-2020-3580
hackerone·2021-09-29·CVSS 6.1
CVE-2020-3580 [MEDIUM] ███████ - XSS - CVE-2020-3580
███████ - XSS - CVE-2020-3580
████ appears to be affected by the Cisco ASA XSS CVE-2020-3580, This vulnerablity is targets the saml service within the VPN. It is triggered via a POST request to /+CSCOE+/saml/sp/acs?tgname=a
## References
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-multiple-FCB3vPZe
## Impact
With this vulnerability, an attacker can for example steal users cookies or redirect users on malicious website.
## System Host(s)
██████████
## Affected Product(s) and Version(s)
Cisco ASA
## CVE Numbers
CVE-2020-3580
## Steps to Reproduce
send a POST request from browser:
POST /+CSCOE+/saml/sp/acs?tgname=a HTTP/1.1
Host: █████
Connection: close
sec-ch-ua: " Not;A Brand";v="99", "Google Chrome";v="91", "Chromium";v="91"
sec-ch-ua-
HackerOne
XSS due to CVE-2020-3580 [███]
hackerone·2021-09-09·CVSS 6.1
CVE-2020-3580 [MEDIUM] XSS due to CVE-2020-3580 [███]
XSS due to CVE-2020-3580 [███]
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device.
Steps To Reproduce
Go to this URL
http://www.info-sec.cl/post-xss-███.html
HTML POC:
history.pushState('', '', '/')
document.forms[0].submit();
## Impact
- An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link.
- A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-base
HackerOne
XSS due to CVE-2020-3580 [██████]
hackerone·2021-09-09·CVSS 6.1
CVE-2020-3580 [MEDIUM] XSS due to CVE-2020-3580 [██████]
XSS due to CVE-2020-3580 [██████]
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device.
Steps To Reproduce
Go to this URL
http://www.info-sec.cl/post-xss-███████.html
HTML POC:
history.pushState('', '', '/')
document.forms[0].submit();
## Impact
- An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link.
- A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, brows
HackerOne
XSS due to CVE-2020-3580 [███.mil]
hackerone·2021-08-19·CVSS 6.1
CVE-2020-3580 [MEDIUM] XSS due to CVE-2020-3580 [███.mil]
XSS due to CVE-2020-3580 [███.mil]
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device.
Steps To Reproduce
Go to this URL
██████████████.mil.html
HTML POC:
history.pushState('', '', '/')
document.forms[0].submit();
## Impact
- An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link.
- A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information
HackerOne
XSS DUE TO CVE-2020-3580
hackerone·2021-07-29·CVSS 6.1
CVE-2020-3580 [MEDIUM] XSS DUE TO CVE-2020-3580
XSS DUE TO CVE-2020-3580
Hello Team,
During my research, I found the following host to be vulnerable to CVE 2020-3580 which is POST BASED XSS.
Vulnerable URL: https://████/+CSCOE+/saml/sp/acs?tgname=a
## Impact
Attackers can steal cookies and even takeover accounts and perform different malicious activities.
## System Host(s)
███
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Save following code as xss.html and open in browser:
history.pushState('', '', '/')
document.forms[0].submit();
## Suggested Mitigation/Remediation Actions
HackerOne
XSS DUE TO CVE-2020-3580
hackerone·2021-07-29·CVSS 6.1
CVE-2020-3580 [MEDIUM] XSS DUE TO CVE-2020-3580
XSS DUE TO CVE-2020-3580
Hello Team,
During my research, I found the following host to be vulnerable to CVE 2020-3580 which is POST BASED XSS.
Vulnerable URL: https://█████/+CSCOE+/saml/sp/acs?tgname=a
## Impact
Attackers can steal cookies and even takeover accounts and perform different malicious activities.
## System Host(s)
███
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Save Following code as xss.html and open in any browser:
history.pushState('', '', '/')
document.forms[0].submit();
## Suggested Mitigation/Remediation Actions
CWE
Improper Input Validation
mitre_cwe
CWE-20 Improper Input Validation
CWE-20: Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
Input validation is a frequently-used technique
for checking potentially dangerous inputs in order to
ensure that the inputs are safe for processing within the
code, or when communicating with other components. Input can consist of: raw data - strings, numbers, parameters, file contents, etc. metadata - information about the raw data, such as headers or size Data can be simple or structured. Structured data
can be composed of many nested layers, composed of
combinations of metadata and raw data, with other simple or
structured data. Many properties of raw data or metadata may n
CWE
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
mitre_cwe
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
There are many variants of cross-site scripting, characterized by a variety of terms or involving different attack topologies. However, they all indicate the same fundamental weakness: improper neutralization of dangerous input between the adversary and a victim.
Background: The Same Origin Policy states that browsers should limit the resources accessible to scripts running on a given web site, or "origin", to the resources associated with that web site on the client-side, and not the client-side resources of any other sites or
2020-10-21
Published
2021-11-03
Added to CISA KEV
Exploited in the wild