Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 7, 2024

CVE-2020-3259

High
EPSS 69.7%CISA KEVRansomware
Cisco/Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

EPSS — Exploit Probability

69.7%

Higher than 98.6% of all CVEs

Required Action

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMB; https://nvd.nist.gov/vuln/detail/CVE-2020-3259

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
69.7%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Feb 15, 2024

Added to KEV

Feb 15, 2024

Remediation Due

Mar 7, 2024

Affected Product

Cisco

Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

View all Cisco CVEs