Skip to content
VulniPulse
High7.5Cisco Exploited CISA KEV

High [CVE-2020-3259] Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

This high-severity Cisco advisory covers CVE-2020-3259 affecting Secure Firewall Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software.

CVE-2020-3259 Published May 6, 2020Updated by vendor Feb 21, 2024
Affected products & platforms
CiscoFirewallASA / Firepower
Open vendor advisory

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

An unauthenticated remote attacker could exploit a flaw in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information.

The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface.

Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; Secure Firewall Threat Defense (FTD) Software.

CISA Known Exploited Vulnerability

Listed:
Feb 15, 2024 · federal remediation due Mar 7, 2024
Required action:
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Ransomware use:
Known

KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.

Affected versions
  • Scope: This vulnerability affects Cisco products if they are running a vulnerable release of Cisco ASA Software or FTD Software with a vulnerable AnyConnect or WebVPN configuration. Cisco ASA Software
  • Earlier than 9.51 — Migrate to a fixed release
  • 9.51 — Migrate to a fixed release
  • 9.6 — 9.6.4.41 / Migrate to a fixed release
  • 9.71 — Migrate to a fixed release
  • Release 9.8 (first fixed: 9.8.4.20)
  • Release 9.9 (first fixed: 9.9.2.67)
  • Release 9.10 (first fixed: 9.10.1.40)
  • Release 9.12 (first fixed: 9.12.3.9)
  • Release 9.13 (first fixed: 9.13.1.10)
  • Earlier than 6.2.31 — Migrate to a fixed release
  • Release 6.2.3 (first fixed: 6.2.3.16 (June 2020) / Cisco_FTD_Hotfix_DT-6.2.3.16-3.sh.REL.tar)
  • Release Cisco_FTD_SSP_FP2K_Hotfix_DT-6.2.3.16-3.sh.REL.tar (first fixed: Cisco_FTD_SSP_Hotfix_DT-6.2.3.16-3.sh.REL.tar / 6.2.3.16 (June 2020))
  • Release Cisco_FTD_Hotfix_DT-6.2.3.16-3.sh.REL.tar (first fixed: Cisco_FTD_SSP_FP2K_Hotfix_DT-6.2.3.16-3.sh.REL.tar / Cisco_FTD_SSP_Hotfix_DT-6.2.3.16-3.sh.REL.tar)
  • Release 6.3.0 (first fixed: 6.3.0.6 (future release) / Cisco_FTD_Hotfix_AO-6.3.0.6-2.sh.REL.tar)
  • Release Cisco_FTD_SSP_FP2K_Hotfix_ AO-6.3.0.6-2.sh.REL.tar (first fixed: Cisco_FTD_SSP_Hotfix_ AO-6.3.0.6-2.sh.REL.tar / 6.3.0.6 (future release))
  • Release Cisco_FTD_Hotfix_AO-6.3.0.6-2.sh.REL.tar (first fixed: Cisco_FTD_SSP_FP2K_Hotfix_ AO-6.3.0.6-2.sh.REL.tar / Cisco_FTD_SSP_Hotfix_ AO-6.3.0.6-2.sh.REL.tar)
  • Release 6.4.0 (first fixed: 6.4.0.9)
  • Release 6.5.0 (first fixed: 6.5.0.5 (future release) / Cisco_FTD_Hotfix_H-6.5.0.5-2.sh.REL.tar and later)
  • Release Cisco_FTD_SSP_FP1K_Hotfix_H-6.5.0.5-2.sh.REL.tar and later (first fixed: Cisco_FTD_SSP_FP2K_Hotfix_H-6.5.0.5-2.sh.REL.tar and later / Cisco_FTD_SSP_Hotfix_H-6.5.0.5-2.sh.REL.tar and later)
  • Release 6.5.0.5 (future release) (first fixed: Cisco_FTD_Hotfix_H-6.5.0.5-2.sh.REL.tar and later / Cisco_FTD_SSP_FP1K_Hotfix_H-6.5.0.5-2.sh.REL.tar and later)
  • Release Cisco_FTD_SSP_FP2K_Hotfix_H-6.5.0.5-2.sh.REL.tar and later (first fixed: Cisco_FTD_SSP_Hotfix_H-6.5.0.5-2.sh.REL.tar and later / 6.6.0)

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions
  • 9.8.4.20
  • 9.9.2.67
  • 9.10.1.40
  • 9.12.3.9
  • 9.13.1.10
  • 6.2.3.16 (June 2020) / Cisco_FTD_Hotfix_DT-6.2.3.16-3.sh.REL.tar
  • Cisco_FTD_SSP_Hotfix_DT-6.2.3.16-3.sh.REL.tar / 6.2.3.16 (June 2020)
  • Cisco_FTD_SSP_FP2K_Hotfix_DT-6.2.3.16-3.sh.REL.tar / Cisco_FTD_SSP_Hotfix_DT-6.2.3.16-3.sh.REL.tar
  • 6.3.0.6 (future release) / Cisco_FTD_Hotfix_AO-6.3.0.6-2.sh.REL.tar
  • Cisco_FTD_SSP_Hotfix_ AO-6.3.0.6-2.sh.REL.tar / 6.3.0.6 (future release)
  • Cisco_FTD_SSP_FP2K_Hotfix_ AO-6.3.0.6-2.sh.REL.tar / Cisco_FTD_SSP_Hotfix_ AO-6.3.0.6-2.sh.REL.tar
  • 6.4.0.9
  • 6.5.0.5 (future release) / Cisco_FTD_Hotfix_H-6.5.0.5-2.sh.REL.tar and later
  • Cisco_FTD_SSP_FP2K_Hotfix_H-6.5.0.5-2.sh.REL.tar and later / Cisco_FTD_SSP_Hotfix_H-6.5.0.5-2.sh.REL.tar and later
  • Cisco_FTD_Hotfix_H-6.5.0.5-2.sh.REL.tar and later / Cisco_FTD_SSP_FP1K_Hotfix_H-6.5.0.5-2.sh.REL.tar and later
  • Cisco_FTD_SSP_Hotfix_H-6.5.0.5-2.sh.REL.tar and later / 6.6.0

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
  • Earlier than 9.51: migrate to a fixed release.
  • Release 9.51: migrate to a fixed release.
  • Release 9.6: 9.6.4.41 / Migrate to a fixed release.
  • Release 9.71: migrate to a fixed release.
  • Release 9.8: upgrade to 9.8.4.20.
  • Release 9.9: upgrade to 9.9.2.67.
  • Release 9.10: upgrade to 9.10.1.40.
  • Release 9.12: upgrade to 9.12.3.9.
Workaround status
  • There are no workarounds that address this vulnerability.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.