← Back to browse · API

CVE-2020-3580

Severity
MEDIUM
CVSS
6.1
EPSS
0.85576
Risk score
79.35
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-24851, GHSA-RR9H-G433-576P
Products
Cisco:Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Cisco:Cisco Adaptive Security Appliance (ASA) Software n/a
Sources
euvd EUVD-2020-24851
cisa.gov CVE-2020-3580

Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

References