← Vulnerability feed

Vulnerability record · CVE-2020-3580 · published 21 October 2020

CVE-2020-3580: Cisco ASA and FTD web services interface XSS

Cisco · Secure Firewall Threat Defense

The web services interface of Cisco ASA and FTD software fails to validate user-supplied input, allowing reflected cross-site scripting. The flaw affects only specific AnyConnect and WebVPN configurations, and an attacker must convince a user of the interface to click a crafted link. Because the interface is internet-facing on many deployments, successful exploitation can run script in the context of the victim's session.

6.1 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 Known ransomware use EPSS 86% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 2.6
86%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
11 Aug 2026Last modified by NVD

Description

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with known ransomware use and near-maximum EPSS, but requires user interaction and is rated medium severity by CVSS.

What it is

The web services interface of Cisco ASA and FTD software fails to validate user-supplied input, allowing reflected cross-site scripting. The flaw affects only specific AnyConnect and WebVPN configurations, and an attacker must convince a user of the interface to click a crafted link. Because the interface is internet-facing on many deployments, successful exploitation can run script in the context of the victim's session.

Impact

An attacker can execute arbitrary script in the context of the web services interface or read sensitive browser-based information. This can enable session theft or actions performed as the targeted user, though the record does not describe further privilege escalation.

Attack surface

Reached over the network through the ASA/FTD web services interface; no authentication is required by the attacker, but user interaction (clicking a crafted link) is required per the CVSS vector and description. Only specific AnyConnect and WebVPN configurations are affected.

Exploitation

CVE-2020-3580 is listed in CISA KEV with known ransomware campaign use, and EPSS shows a 30-day probability of 0.856 (99.7th percentile), indicating active exploitation in the wild. The vendor advisory is tagged Patch and Vendor Advisory.

What to do

  • Apply the Cisco security advisory updates for ASA and FTD software as the primary fix.
  • If patching cannot be done immediately, restrict or disable unnecessary AnyConnect and WebVPN web services exposure to the internet.
  • Require users to reach the web services interface only over trusted networks or VPN, reducing the chance of clicking crafted links.
  • Review Cisco guidance for the specific AnyConnect and WebVPN configurations listed as vulnerable and confirm whether your deployment matches.
  • Monitor vendor advisories for updated fixed software versions.

Detection

  • Inspect web services interface access logs for requests containing script-like payloads in URL parameters or query strings.
  • Alert on unexpected outbound or referrer traffic from users of the ASA/FTD web interface that could indicate script execution or data exfiltration.
  • Correlate KEV status with asset inventory to confirm which ASA and FTD devices run affected AnyConnect or WebVPN configurations.
  • Review browser or proxy logs for requests to the ASA/FTD web services interface with encoded or obfuscated parameters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3580 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3580), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.