CVE-2020-3259
Cisco ASA and FTD Information Disclosure Vulnerability
⚠ KEVEPSS 71.8%
描述
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
如何修補 CVE-2020-3259
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2020-3259 正在被利用嗎?
是 — CVE-2020-3259 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。