Cisco ASA Software and FTD Software Web Services Interface XSS (cisco-sa-asaftd-xss-multiple-FCB3vPZe) (Direct Check)

medium Nessus Plugin ID 151442

Synopsis

The web application running on the remote web server is affected by a cross-site scripting vulnerability.

Description

The version of Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software running on the remote web server is affected by a cross-site scripting vulnerability. An unauthenticated, remote attacker can exploit this, by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session.
Please see the included Cisco BID and Cisco Security Advisory for more information.

Solution

Upgrade the device software in accordance with the advisory.

See Also

http://www.nessus.org/u?4f256d96

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu75581

Plugin Details

Severity: Medium

ID: 151442

File Name: cisco_asa_cve-2020-3580.nbin

Version: 1.37

Type: remote

Family: CISCO

Published: 7/7/2021

Updated: 3/19/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.6

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2020-3580

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:firepower_threat_defense, cpe:/a:cisco:adaptive_security_appliance_software

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/21/2021

Vulnerability Publication Date: 10/21/2020

CISA Known Exploited Vulnerability Due Dates: 5/3/2022

Reference Information

CVE: CVE-2020-3580