The flaw is classified as CWE-79 and results from insufficient validation of user-supplied input by the web services interface. Cisco describes the high-level attack flow as an attacker presenting a crafted link, a user clicking it while using the affected interface, and script then executing in the interface context.
Cisco lists these potentially affected Cisco ASA configurations:
- AnyConnect Internet Key Exchange Version 2 (IKEv2) Remote Access with client services enabled, using
crypto ikev2 enable client-services port.
- AnyConnect SSL VPN with
webvpn and enable configured.
- Clientless SSL VPN with
webvpn and enable configured.
For Cisco FTD, Cisco lists AnyConnect IKEv2 Remote Access with client services enabled and AnyConnect SSL VPN as potentially affected configurations. The flaw applies only to deployments with specific AnyConnect or WebVPN configurations, not to every ASA or FTD deployment. The reviewed advisory does not identify the vulnerable input field, a specific endpoint, or the internal implementation detail responsible for the insufficient validation.