CVE-2020-3259High· 7.5▾ Abyssal⚠ Exploited in the wildA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 41.3 · likelihood 14.4 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Mar 7, 2024
Last analysed / modified upstream
69%
69% → 72%
Added to the CISA catalog on Feb 15, 2024. Federal remediation due Mar 7, 2024. View catalog ↗
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
secure_firewall_threat_defense >= 6.2.3, < 6.2.3.16secure_firewall_threat_defense >= 6.3.0, < 6.3.0.6secure_firewall_threat_defense >= 6.4.0, < 6.4.0.9secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5adaptive_security_appliance_software >= 9.8, < 9.8.4.20adaptive_security_appliance_software >= 9.9, < 9.9.2.67adaptive_security_appliance_software >= 9.10, < 9.10.1.40adaptive_security_appliance_software >= 9.12, < 9.12.3.9adaptive_security_appliance_software >= 9.13, < 9.13.1.10Upgrade past the affected range:
secure_firewall_threat_defense 6.5.0.5adaptive_security_appliance_software 9.13.1.10Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …
CVE-2020-3452High· 7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…
CVE-2018-15454High· 8.6A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an …
CVE-2025-20224Medium· 5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…
CVE-2026-20012High· 8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Softwar…
CVE-2026-76460Critical· 10.0A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint