216.73.216.233

CVE-2020-3259

· Published 15/02/2024 01:00 · Modified 21/12/2025 07:17 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2020-3259

Essential information

Published
15/02/2024 01:00
Modified
21/12/2025 07:17
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CISA KEV
Yes
CWE

Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

NVD status

NVD
View on NVD