CVE-2020-3561Medium· 4.7▾ SunlitA vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system. The vulnerability is due to improper input sanitization. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to conduct a CRLF injection attack, adding arbitrary HTTP headers in the responses of the system and redirecting the user to arbitrary websites.
adaptive_security_appliance < 9.6.4.35secure_firewall_threat_defense < 6.3.0.6secure_firewall_threat_defense >= 6.4.0, < 6.4.0.10secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5secure_firewall_threat_defense >= 6.6.0, < 6.6.1adaptive_security_appliance_software >= 9.8.0, < 9.8.4.20adaptive_security_appliance_software >= 9.9.0, < 9.9.2.80adaptive_security_appliance_software >= 9.10.0, < 9.10.1.43adaptive_security_appliance_software >= 9.12.0, < 9.12.3.9adaptive_security_appliance_software >= 9.13.0, < 9.13.1.10adaptive_security_appliance_software >= 9.14.0, < 9.14.1.10Upgrade past the affected range:
adaptive_security_appliance 9.6.4.35secure_firewall_threat_defense 6.6.1adaptive_security_appliance_software 9.14.1.10Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20130Critical· 10.0As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…
CVE-2020-3572High· 8.6A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…
CVE-2020-3564Medium· 5.3A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection
CVE-2020-3555Medium· 6.8A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affecte…
CVE-2020-3554High· 7.5A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…
CVE-2020-3529High· 8.6A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected de…