What is CVE-2020-3580?
CyStack AICisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software contain an XSS flaw in their web services interface when specific AnyConnect or WebVPN configurations are enabled. An unauthenticated remote attacker can use a crafted link and persuade a user to click it, causing script execution in the interface context or access to sensitive browser-based information. Cisco states that public exploit code exists and that the vulnerability is being actively exploited. Exposure must be checked against both the software branch and the enabled VPN configuration; Cisco has confirmed that FMC Software is not affected.
