Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 3, 2022

CVE-2020-3580

High
EPSS 92.6%CISA KEVRansomware
Cisco/Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

EPSS — Exploit Probability

92.6%

Higher than 99.7% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2020-3580

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
92.6%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

May 3, 2022

Affected Product

Cisco

Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

View all Cisco CVEs