← Vulnerability feed

Vulnerability record · CVE-2020-3259 · published 6 May 2020

CVE-2020-3259: Cisco ASA and FTD web services memory disclosure via crafted URL

Cisco · Secure Firewall Threat Defense

Cisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects only specific AnyConnect and WebVPN configurations, but exposes confidential data from the device. It is remotely reachable without authentication and is listed in CISA KEV.

7.5 CVSS 3.1 High CISA KEV since 15 Feb 2024 Known ransomware use EPSS 72% · top 0.6% CWE-200 · Information exposure
7.5CVSS 3.1 base score, v2 5.0
72%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and is remotely exploitable without authentication.

What it is

Cisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects only specific AnyConnect and WebVPN configurations, but exposes confidential data from the device. It is remotely reachable without authentication and is listed in CISA KEV.

Impact

An unauthenticated remote attacker can retrieve device memory contents, potentially exposing credentials, session data or other confidential information. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached over the network through the web services interface by sending a crafted GET request with an invalid URL. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CISA added it to KEV on 2024-02-15 with known ransomware campaign use, and EPSS is 0.71789 (99.4th percentile), indicating active exploitation is expected or observed.

What to do

  • Apply the Cisco vendor advisory patches for ASA and FTD immediately.
  • If patching is not possible, restrict or disable the web services interface and AnyConnect/WebVPN exposure per vendor guidance.
  • Limit internet-facing access to the web services interface to trusted management networks.
  • Monitor for and block crafted GET requests with malformed URLs targeting the web services interface.
  • Review KEV required action and discontinue use if mitigations are unavailable.

Detection

  • Inspect web services logs for GET requests containing malformed or invalid URL patterns.
  • Alert on anomalous memory-disclosure indicators or unexpected data returned from the web services interface.
  • Correlate network traffic to ASA/FTD web services with known exploitation attempts.
  • Monitor for post-exploitation use of disclosed credentials or session data.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3259 to the Known Exploited Vulnerabilities catalog on 15 February 2024 as "Cisco ASA and FTD Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 March 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3259 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3259), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.