PT-2024-9151 · Cisco · Cisco Asa+1

Amit Laish

+1

·

Published

2024-10-23

·

Updated

2024-11-01

·

CVE-2024-20341

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description: A vulnerability in the VPN web client services feature could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This issue is due to improper validation of user-supplied input to application endpoints. An attacker could exploit this by persuading a user to follow a link designed to submit malicious input to the affected application, potentially allowing the attacker to execute arbitrary HTML or script code in the browser in the context of the web services page.
Recommendations: For Cisco Adaptive Security Appliance (ASA) Software, update to a version that includes the fix for this issue. For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the VPN web client services feature until a patch is available. Avoid using links from untrusted sources to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-10838
CVE-2024-20341

Affected Products

Cisco Asa
Cisco Ftd