PT-2020-4701 · Cisco · Cisco Ftd+1

Published

2020-10-21

·

Updated

2022-05-26

·

CVE-2020-3578

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Adaptive Security Appliance (ASA) Software versions prior to the fixed release Cisco Firepower Threat Defense (FTD) Software versions prior to the fixed release
Description The issue is related to insufficient validation of URLs when portal access rules are configured in the web services interface of the affected software. This could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are supposed to be blocked. An attacker could exploit this by accessing certain URLs on the affected device.
Recommendations For Cisco Adaptive Security Appliance (ASA) Software, update to the fixed release. For Cisco Firepower Threat Defense (FTD) Software, update to the fixed release. As a temporary workaround, consider restricting access to the WebVPN portal until a patch is available. Avoid accessing certain URLs on the affected device that could be used to exploit the issue.

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05253
CVE-2020-3578

Affected Products

Cisco Asa
Cisco Ftd