CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: May 3, 2022
CVE-2020-3580
Description
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
EPSS — Exploit Probability
Higher than 99.7% of all CVEs
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2020-3580
Risk Assessment
CRITICALDetails
- Severity
- High
- EPSS
- 92.6%
- CISA KEV
- Yes
- Ransomware
- Known
- Articles
- 0
Timeline
Published
Nov 3, 2021
Added to KEV
Nov 3, 2021
Remediation Due
May 3, 2022
Affected Product
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
View all Cisco CVEs