PT-2024-9151 · Cisco · Cisco Asa+1
Amit Laish
+1
·
Published
2024-10-23
·
Updated
2024-11-01
·
CVE-2024-20341
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description:
A vulnerability in the VPN web client services feature could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This issue is due to improper validation of user-supplied input to application endpoints. An attacker could exploit this by persuading a user to follow a link designed to submit malicious input to the affected application, potentially allowing the attacker to execute arbitrary HTML or script code in the browser in the context of the web services page.
Recommendations:
For Cisco Adaptive Security Appliance (ASA) Software, update to a version that includes the fix for this issue.
For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the VPN web client services feature until a patch is available.
Avoid using links from untrusted sources to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd