Vulnerability record · CVE-2020-3259 · published 6 May 2020
CVE-2020-3259: Cisco ASA and FTD web services memory disclosure via crafted URL
Cisco · Secure Firewall Threat Defense
Cisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects only specific AnyConnect and WebVPN configurations, but exposes confidential data from the device. It is remotely reachable without authentication and is listed in CISA KEV.
Description
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and is remotely exploitable without authentication.
What it is
Cisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects only specific AnyConnect and WebVPN configurations, but exposes confidential data from the device. It is remotely reachable without authentication and is listed in CISA KEV.
Impact
An unauthenticated remote attacker can retrieve device memory contents, potentially exposing credentials, session data or other confidential information. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network through the web services interface by sending a crafted GET request with an invalid URL. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA added it to KEV on 2024-02-15 with known ransomware campaign use, and EPSS is 0.71789 (99.4th percentile), indicating active exploitation is expected or observed.
What to do
- Apply the Cisco vendor advisory patches for ASA and FTD immediately.
- If patching is not possible, restrict or disable the web services interface and AnyConnect/WebVPN exposure per vendor guidance.
- Limit internet-facing access to the web services interface to trusted management networks.
- Monitor for and block crafted GET requests with malformed URLs targeting the web services interface.
- Review KEV required action and discontinue use if mitigations are unavailable.
Detection
- Inspect web services logs for GET requests containing malformed or invalid URL patterns.
- Alert on anomalous memory-disclosure indicators or unexpected data returned from the web services interface.
- Correlate network traffic to ASA/FTD web services with known exploitation attempts.
- Monitor for post-exploitation use of disclosed credentials or session data.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3259 to the Known Exploited Vulnerabilities catalog on 15 February 2024 as "Cisco ASA and FTD Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 March 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-3259 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3259), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.