Cisco ASA Exposure of Sensitive Information to an Unauthorized Actor (CVE-2020-3259)

high Tenable OT Security Plugin ID 506194

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?8650ff40

http://www.nessus.org/u?ca70b7e2

Plugin Details

Severity: High

ID: 506194

File Name: tenable_ot_cisco_CVE-2020-3259.nasl

Version: 1.3

Type: Remote

Family: Tenable.ot

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 6

Percentile: 96.65

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2020-3259

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:adaptive_security_appliance_software:9

Required KB Items: Tenable.ot/Cisco

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/6/2020

Vulnerability Publication Date: 5/6/2020

CISA Known Exploited Vulnerability Due Dates: 3/7/2024

Reference Information

CVE: CVE-2020-3259

CWE: 200