← Back to browse · API

CVE-2020-3259

Severity
HIGH
CVSS
7.5
EPSS
0.69336
Risk score
79.27
CISA KEV
Yes
PoC
No
Published
2024-02-15
Modified
2024-02-15
First seen
2026-08-07
Aliases
EUVD-2020-24530, GHSA-VW99-PF8W-G3CW
Products
Cisco:Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Cisco:Cisco Adaptive Security Appliance (ASA) Software n/a
Sources
euvd EUVD-2020-24530
cisa.gov CVE-2020-3259

Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

References