ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco ASA Flaw Under Active Attack After PoC Exploit Posted Online

highExploit / PoC exploited in the wildimportance 60CVE-2020-3580

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3580
Cross-Site Scripting in Cisco ASA and FTD Web Services Interface

CVE-2020-3580 is a cross-site scripting (XSS) flaw caused by insufficient validation of user-supplied input in the web services interface of Cisco ASA and Firepower Threat Defense (FTD) software. An unauthenticated, remote attacker can exploit it by persuading a user of the web interface to click a crafted link, which then executes arbitrary script code in the context of the interface or exposes sensitive browser-based information such as session data. Only devices running specific AnyConnect and WebVPN configurations are affected, so not every ASA/FTD deployment is vulnerable. The flaw is under active exploitation: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, a public PoC exploit has driven scanning, and groups such as Akira and LockBit are actively searching for vulnerable Cisco ASA devices.

Do: Apply updates per the vendor's instructions (Cisco's advisory lists the fixed ASA/FTD releases), prioritizing internet-facing devices since ransomware operators (Akira, LockBit) are actively scanning. Check whether the web services interface (AnyConnect/WebVPN) is enabled, as only those configurations are vulnerable, and restrict internet access to the device's management/web interface where possible. Treat as urgent given its KEV listing and known ransomware use.

6.186% KEV ransomware
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass≈100,000–1,000,000 internet-exposed ASA/FTD appliances (Cisco ASA is among the most commonly exposed edge firewall/VPN platforms in public internet scans)
Full article278 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 28, 2021

A security vulnerability in Cisco Adaptive Security Appliance (ASA) that was addressed by the company last October, and again earlier this April, has been subjected to active in-the-wild attacks following the release of proof-of-concept (PoC) exploit code.

The PoC was published by researchers from cybersecurity firm Positive Technologies on June 24, following which reports emerged that attackers are chasing after an exploit for the bug.

"Tenable has also received a report that attackers are exploiting CVE-2020-3580 in the wild," the cyber exposure company said.

Tracked as CVE-2020-3580 (CVSS score: 6.1), the issue concerns multiple vulnerabilities in the web services interface of Cisco ASA software and Cisco Firepower Threat Defense (FTD) software that could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks on an affected device.

As of July 2020, there were a little over 85,000 ASA/FTD devices, 398 of which are spread across 17% of the Fortune 500 companies, according to cybersecurity company Rapid7.

Successful exploitation, such as scenarios where a user of the interface is convinced to click a specially-crafted link, could permit the adversary to execute arbitrary JavaScript code in the context of the interface or access sensitive, browser-based information.

Although Cisco remediated the flaw in October 2020, the network equipment company subsequently determined the fix to be "incomplete," thereby requiring a second round of patches that were released on April 28, 2021.

In light of public PoC availability, it's recommended that organizations prioritize patching CVE-2020-3580 to mitigate the risk associated with the flaw.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/06/cisco-asa-flaw-under-active-attack.html