CVE-2020-3259
Cisco ASA and FTD Information Disclosure Vulnerability
⚠ KEVEPSS 71.8%
Description
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
How to fix CVE-2020-3259
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2020-3259 being exploited?
Yes — CVE-2020-3259 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.