Hackers target Cisco ASA after a PoC exploit code was published online
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3580 | Cross-Site Scripting in Cisco ASA and FTD Web Services Interface CVE-2020-3580 is a cross-site scripting (XSS) flaw caused by insufficient validation of user-supplied input in the web services interface of Cisco ASA and Firepower Threat Defense (FTD) software. An unauthenticated, remote attacker can exploit it by persuading a user of the web interface to click a crafted link, which then executes arbitrary script code in the context of the interface or exposes sensitive browser-based information such as session data. Only devices running specific AnyConnect and WebVPN configurations are affected, so not every ASA/FTD deployment is vulnerable. The flaw is under active exploitation: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, a public PoC exploit has driven scanning, and groups such as Akira and LockBit are actively searching for vulnerable Cisco ASA devices. Do: Apply updates per the vendor's instructions (Cisco's advisory lists the fixed ASA/FTD releases), prioritizing internet-facing devices since ransomware operators (Akira, LockBit) are actively scanning. Check whether the web services interface (AnyConnect/WebVPN) is enabled, as only those configurations are vulnerable, and restrict internet access to the device's management/web interface where possible. Treat as urgent given its KEV listing and known ransomware use. | 6.1 | 86% | KEV ransomware |
| mass≈100,000–1,000,000 internet-exposed ASA/FTD appliances (Cisco ASA is among the most commonly exposed edge firewall/VPN platforms in public internet scans) |
Full article311 words · extracted from securityaffairs.com · click to collapse

Experts warn of attacks against Cisco ASA devices after researchers have published a PoC exploit code on Twitter for a known XSS vulnerability.
Experts warn of attacks against Cisco ASA devices after researchers from Positive Technologies have published a PoC exploit code on Twitter for the CVE-2020-3580 XSS vulnerability.
— PT SWARM (@ptswarm) June 24, 2021🎁PoC for XSS in Cisco ASA (CVE-2020-3580)
POST /+CSCOE+/saml/sp/acs?tgname=a HTTP/1.1
Host: ciscoASA.local
Content-Type: application/x-www-form-urlencoded
Content-Length: 44SAMLResponse="><svg/onload=alert('PTSwarm')> pic.twitter.com/c53MKSK9bg
Tenable experts published an alert about the availability of the PoC exploit for the XSS, they said that after Positive Technologies published it, other researchers are chasing bug bounties for this issue. Tenable also warned of attacks in the wild exploiting the CVE-2020-3580 flaw.
“Shortly after, Mikhail Klyuchnikov, a researcher at Positive Technologies also tweeted that other researchers are chasing bug bounties for this vulnerability. Tenable has also received a report that attackers are exploiting CVE-2020-3580 in the wild.” reads the alert published by Tenable. alert. “With this new information, Tenable recommends that organizations prioritize patching CVE-2020-3580.”
Tenable researchers explained that successful exploitation would allow the attacker to execute arbitrary code within the interface and access sensitive information.
Researchers pointed out that in a real attack scenario, successful exploitation of this vulnerability requires an attacker to trick an administrative user to login and navigate to the webpage where he implanted the malicious code.
“To exploit any of these vulnerabilities, an attacker would need to convince “a user of the interface” to click on a specially crafted link. Successful exploitation would allow the attacker to execute arbitrary code within the interface and access sensitive, browser-based information.” continues Tenable.
Organizations have to install security updates that address the flaw to prevent attacks exploiting the issue.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Cisco ASA)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/119442/hacking/cisco-asa-under-attack.html