CVE-2020-3259: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
EPSS71.7%KEV 1739件中713位
CVEの年2020追加まで約4年
同じベンダーの登録100
同じ製品の登録6
| 項目 | 内容 |
|---|---|
| ベンダー | Cisco |
| 製品 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| 脆弱性の名前 | Cisco ASA and FTD Information Disclosure Vulnerability |
| KEVへの追加日 | 2024年2月15日 |
| 米政府機関の対応期限 | 2024年3月7日 |
| ランサムウェアでの悪用 | 確認あり |
| CWE | CWE-200 |
CISAの説明(英語)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
同じ製品のほかの登録
| CVE | ベンダー・製品 | 追加日 | EPSS | ランサムウェア |
|---|---|---|---|---|
| CVE-2024-20481 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024年10月24日 | 15.8% | 不明 |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024年4月24日 | 19.4% | 不明 |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024年4月24日 | 70.6% | 不明 |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2021年11月3日 | 85.5% | 確認あり |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2021年11月3日 | 99.9% | 不明 |
CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて
2024年2月15日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、CiscoのAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)の脆弱性です。