Record summary
A quick snapshot of what this page covers.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2020-3259
- Vendor/project
- Cisco
- Product
- Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
- Vulnerability name
- Cisco ASA and FTD Information Disclosure Vulnerability
- Date added
- 2024-02-15
- Due date
- 2024-03-07
- Known ransomware campaign use
- Known
Exploit context
What the vulnerability is about.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
Source
Where this page information comes from.
Original source
Original source links
Open the public records and source datasets used for this page.
