Cisco ASA and FTD Web Services Interface XSS Enables Script Execution and Browser Information Access

What is CVE-2020-3580?

CyStack AI

Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software contain an XSS flaw in their web services interface when specific AnyConnect or WebVPN configurations are enabled. An unauthenticated remote attacker can use a crafted link and persuade a user to click it, causing script execution in the interface context or access to sensitive browser-based information. Cisco states that public exploit code exists and that the vulnerability is being actively exploited. Exposure must be checked against both the software branch and the enabled VPN configuration; Cisco has confirmed that FMC Software is not affected.

Overview

Original source data

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

Technical details

The defect is insufficient validation of user-supplied input by the device web services interface and is classified as CWE-79. The attack is reachable over the network without attacker authentication, but requires a user of the interface to click a crafted link. On ASA, Cisco identifies AnyConnect Internet Key Exchange Version 2 remote access with client services, AnyConnect SSL VPN, and clientless SSL VPN as vulnerable configurations; on FTD, it identifies AnyConnect Internet Key Exchange Version 2 remote access with client services and AnyConnect SSL VPN. The advisory gives the relevant configuration checks as `crypto ikev2 enable` with `client-services port` and `webvpn` with `enable`, depending on the feature. The available evidence does not establish the exact input field, request parameter, or script delivery details.

Impact

Successful exploitation can execute arbitrary script code in the web services interface context or expose sensitive browser-based information. Because execution occurs in the interface context, the affected user's browser session and accessible data may be abused, with confidentiality and integrity consequences for the interface. The available evidence does not establish device operating-system code execution, administrative privilege escalation, or service availability impact. The actual outcome depends on the privileges and data available in the browser of the user who clicks the crafted link.

Remediation

Upgrade affected ASA installations to the branch-specific first fixed release: 9.8.4.34 for 9.8, 9.9.2.85 for 9.9, 9.12.4.13 for 9.12, 9.13.1.21 for 9.13, 9.14.2.8 for 9.14, and 9.15.1.15 for 9.15. For the ASA branches Cisco marks for migration, move to a supported fixed release rather than remaining on that branch. Upgrade FTD 6.4.0 to 6.4.0.12, FTD 6.6.0 to the recommended 6.6.4, and FTD 6.7.0 to 6.7.0.2; migrate the other listed FTD branches to a supported fixed release. Cisco states that no workaround addresses these vulnerabilities. For FTD managed by FMC or FDM, install the upgrade through the relevant management interface and reapply the access control policy after installation. Confirm memory capacity and configuration support before upgrading, and contact Cisco TAC or the maintenance provider if the branch mapping is unclear.

Detection

Inventory every ASA and FTD device, record its software branch and release, and compare the result with the branch-specific fixed releases. On ASA, inspect `show running-config` for `crypto ikev2 enable` with `client-services port`, and for `webvpn` with `enable`; these settings help identify the AnyConnect IKEv2, AnyConnect SSL VPN, and clientless SSL VPN configurations described by Cisco. On FTD, verify whether AnyConnect remote-access VPN or AnyConnect SSL VPN is enabled through FMC or FDM and record the FTD release. Deploy or review Snort rule 57857, which Cisco documents as detecting initial exploit traffic for this XSS issue. Review web services and browser telemetry for suspicious requests or unexpected script activity as a precaution, but the available evidence does not define a complete IOC set or a log event whose absence proves safety.

Sources (9)
cisco (CNA)
cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?%3F%3Futm_campaign=Content+Marketing%3A+Endpoint+Media%2CEvergreen&page=59cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?f%5B0%5D=vendor_project%3A790&f%5B10%5D=vendor_project%3A845&f%5B11%5D=vendor_project%3A848&f%5B12%5D=vendor_project%3A854&f%5B13%5D=vendor_project%3A866&f%5B14%5D=vendor_project%3A877&f%5B15%5D=vendor_project%3A886&f%5B16%5D=vendor_project%3A892&f%5B17%5D=vendor_project%3A893&f%5B18%5D=vendor_project%3A895&f%5B19%5D=vendor_project%3A902&f%5B1%5D=vendor_project%3A792&f%5B20%5D=vendor_project%3A907&f%5B21%5D=vendor_project%3A911&f%5B22%5D=vendor_project%3A917&f%5B23%5D=vendor_project%3A938&f%5B24%5D=vendor_project%3A1042&f%5B2%5D=vendor_project%3A800&f%5B3%5D=vendor_project%3A801&f%5B4%5D=vendor_project%3A812&f%5B5%5D=vendor_project%3A820&f%5B6%5D=vendor_project%3A823&f%5B7%5D=vendor_project%3A831&f%5B8%5D=vendor_project%3A837&f%5B9%5D=vendor_project%3A842&page=6cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?f%5B0%5D=vendor_project%3A793&f%5B10%5D=vendor_project%3A842&f%5B11%5D=vendor_project%3A845&f%5B12%5D=vendor_project%3A854&f%5B13%5D=vendor_project%3A880&f%5B14%5D=vendor_project%3A886&f%5B15%5D=vendor_project%3A893&f%5B16%5D=vendor_project%3A897&f%5B17%5D=vendor_project%3A902&f%5B18%5D=vendor_project%3A903&f%5B19%5D=vendor_project%3A908&f%5B1%5D=vendor_project%3A794&f%5B20%5D=vendor_project%3A917&f%5B21%5D=vendor_project%3A938&f%5B22%5D=vendor_project%3A941&f%5B23%5D=vendor_project%3A942&f%5B24%5D=vendor_project%3A946&f%5B25%5D=vendor_project%3A1147&f%5B26%5D=vendor_project%3A1172&f%5B27%5D=vendor_project%3A1267&f%5B2%5D=vendor_project%3A800&f%5B3%5D=vendor_project%3A801&f%5B4%5D=vendor_project%3A806&f%5B5%5D=vendor_project%3A810&f%5B6%5D=vendor_project%3A817&f%5B7%5D=vendor_project%3A823&f%5B8%5D=vendor_project%3A828&f%5B9%5D=vendor_project%3A837&page=7cisa.govhttps://www.cisa.gov/sites/default/files/2024-10/24_0424_NECP_Webinar_MFA_Slide_Presentation_24_1015_508C.pdfcisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?f%5B0%5D=vendor_project%3A794&f%5B10%5D=vendor_project%3A842&f%5B11%5D=vendor_project%3A845&f%5B12%5D=vendor_project%3A854&f%5B13%5D=vendor_project%3A870&f%5B14%5D=vendor_project%3A880&f%5B15%5D=vendor_project%3A886&f%5B16%5D=vendor_project%3A887&f%5B17%5D=vendor_project%3A898&f%5B18%5D=vendor_project%3A900&f%5B19%5D=vendor_project%3A904&f%5B1%5D=vendor_project%3A800&f%5B20%5D=vendor_project%3A917&f%5B21%5D=vendor_project%3A931&f%5B22%5D=vendor_project%3A932&f%5B23%5D=vendor_project%3A938&f%5B24%5D=vendor_project%3A944&f%5B25%5D=vendor_project%3A1147&f%5B26%5D=vendor_project%3A1151&f%5B27%5D=vendor_project%3A1173&f%5B28%5D=vendor_project%3A1266&f%5B29%5D=vendor_project%3A1267&f%5B2%5D=vendor_project%3A801&f%5B30%5D=vendor_project%3A1275&f%5B3%5D=vendor_project%3A807&f%5B4%5D=vendor_project%3A811&f%5B5%5D=vendor_project%3A813&f%5B6%5D=vendor_project%3A823&f%5B7%5D=vendor_project%3A827&f%5B8%5D=vendor_project%3A832&f%5B9%5D=vendor_project%3A837&page=8
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard