CVE-2020-3259
CVE-2020-3259: 1 tracked advisory record across Cisco. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityHigh7.5
High [CVE-2020-3259] Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
CVE-2020-3259Source published Source updated
An unauthenticated remote attacker could exploit a flaw in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; Secure Firewall Threat Defense (FTD) Software.
- Affected products in this advisory
- Secure Firewall Adaptive Security Appliance (ASA) Software
- Secure Firewall Threat Defense (FTD) Software
- Source-reported affected versions
- Scope: This vulnerability affects Cisco products if they are running a vulnerable release of Cisco ASA Software or FTD Software with a vulnerable AnyConnect or WebVPN configuration. Cisco ASA Software
- Earlier than 9.51 — Migrate to a fixed release
- 9.51 — Migrate to a fixed release
- 9.6 — 9.6.4.41 / Migrate to a fixed release
18 more entries in the full advisory.
- Source-reported fixed versions
- 9.8.4.20
- 9.9.2.67
- 9.10.1.40
- 9.12.3.9
12 more entries in the full advisory.
- Mitigation guidance
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Earlier than 9.51: migrate to a fixed release.
- Release 9.51: migrate to a fixed release.
- Release 9.6: 9.6.4.41 / Migrate to a fixed release.
5 more entries in the full advisory.
- Workarounds
- There are no workarounds that address this vulnerability.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.