Cisco ASA and FTD web services interface XSS enables browser-context script execution

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2020-3580?

CVE-2020-3580 is a vulnerability classified as Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), affecting Cisco Adaptive Security Appliance (ASA) Software. This vulnerability is rated Medium, with a CVSS score of 6.1. This vulnerability has been observed being exploited in the wild.

Overview

Original source data

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

Affected products and scope

A device is affected only when it runs a vulnerable release and has one of the AnyConnect or WebVPN configurations covered by Cisco's advisory.

  • Cisco ASA Software: Cisco lists fixed-release boundaries by train. Train 9.8 is fixed in 9.8.4.34; 9.9 in 9.9.2.85; 9.12 in 9.12.4.13; 9.13 in 9.13.1.21; 9.14 in 9.14.2.8; and 9.15 in 9.15.1.15. Earlier than 9.6, 9.6, 9.7, and 9.10 are directed to migrate to a fixed release. The advisory does not establish the status of ASA trains that it does not list.
  • Cisco FTD Software: Earlier than 6.2.2, 6.2.2, 6.2.3, 6.3.0, and 6.5.0 are directed to migrate to a fixed release. Train 6.4.0 is fixed in 6.4.0.12; train 6.6.0 first received a fix in 6.6.3, but Cisco recommends 6.6.4 because of upgrade issues; and train 6.7.0 is fixed in 6.7.0.2.
  • Cisco Firepower Management Center Software: Cisco confirms that this product is not affected.

These boundaries come from Cisco's fixed-release table. The status of parallel or unlisted trains must not be inferred from a fix in another train.

Technical details

The flaw is classified as CWE-79 and results from insufficient validation of user-supplied input by the web services interface. Cisco describes the high-level attack flow as an attacker presenting a crafted link, a user clicking it while using the affected interface, and script then executing in the interface context.

Cisco lists these potentially affected Cisco ASA configurations:

  • AnyConnect Internet Key Exchange Version 2 (IKEv2) Remote Access with client services enabled, using crypto ikev2 enable client-services port.
  • AnyConnect SSL VPN with webvpn and enable configured.
  • Clientless SSL VPN with webvpn and enable configured.

For Cisco FTD, Cisco lists AnyConnect IKEv2 Remote Access with client services enabled and AnyConnect SSL VPN as potentially affected configurations. The flaw applies only to deployments with specific AnyConnect or WebVPN configurations, not to every ASA or FTD deployment. The reviewed advisory does not identify the vulnerable input field, a specific endpoint, or the internal implementation detail responsible for the insufficient validation.

Exploitability

The vulnerability is reachable over the network without authentication, but requires a user of the interface to click a crafted link. Cisco states that public exploit code exists and that the vulnerability is being actively exploited. CISA includes the vulnerability in its Known Exploited Vulnerabilities Catalog and records it as exploited in the wild, including a known ransomware-use status. Exploitation therefore depends on a user accessing the web interface of a device with an affected configuration.

Technical impact

Exploitation can run arbitrary script in the context of the web interface used by the victim or access sensitive browser-based information. The practical effect depends on the data, session, and permissions available to the user who clicks the crafted link. The available evidence does not describe direct code execution on the ASA or FTD, device-level administrative takeover, or service availability impact. The primary risk is compromise of the browser session and information accessible through the affected interface.

Business impact

Successful exploitation may expose sensitive information that the victim's browser can access during the affected interface session. Malicious script may also alter what the user sees or how the interface behaves in that context, increasing risk for users working with related VPN or management interfaces. The documented impact does not describe service disruption or direct operating-system code execution on the device. Because Cisco confirms public exploit code and active exploitation, identifying devices with affected configurations and upgrading them should be prioritized.

Remediation

  1. Identify the software train and AnyConnect or WebVPN configuration on each ASA and FTD device, then upgrade to the fixed release for that exact train. Cisco lists 9.8.4.34, 9.9.2.85, 9.12.4.13, 9.13.1.21, 9.14.2.8, and 9.15.1.15 for the applicable ASA trains. For FTD, the listed fixed releases include 6.4.0.12, Cisco's recommended 6.6.4, and 6.7.0.2.
  2. For trains that Cisco marks for migration, move to a supported release containing the fix rather than assuming that the existing train is protected.
  3. For FTD managed through Cisco Firepower Management Center, install the upgrade through the FMC interface and reapply the access control policy after installation. For FTD managed through Cisco Firepower Device Manager, install the upgrade through FDM and also reapply the access control policy.
  4. Cisco states that no workaround addresses these vulnerabilities. During upgrade planning, verify that the device has sufficient memory and that the current hardware and software configuration remains supported by the target release.
  5. Because Cisco confirms public exploit code and active exploitation, prioritize remote-access interfaces that are exposed to untrusted users and verify after upgrading that both the installed release and the active configuration match the fixed scope.

Detection

Recommended checks include:

  1. Inventory all Cisco ASA and FTD devices, recording each software release and the enabled remote-access features.
  2. On ASA, review show running-config for crypto ikev2 enable client-services port, and for the webvpn and enable configuration associated with AnyConnect SSL VPN or Clientless SSL VPN.
  3. On FTD, review Remote Access VPN settings in Cisco Firepower Management Center under Devices > VPN > Remote Access or in Cisco Firepower Device Manager under Device > Remote Access VPN.
  4. Compare each software train with the fixed-release boundaries in affected_summary, without inferring the status of trains that Cisco does not list.
  5. Cisco links Snort rules 57857 and 57856 from the advisory. Review whether those rules are applicable to the local monitoring deployment and validate any resulting alerts.

The absence of suspicious events in available logs should not be treated as proof that a device is safe.

Sources (14)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan