LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-3259: Cisco ASA and FTD Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 15, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 7, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-3259 to its Known Exploited Vulnerabilities catalog on Feb 15, 2024, with a federal patch deadline of Mar 7, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which…

CVE-2020-3259 is an information disclosure vulnerability in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. It allows an attacker to retrieve memory contents from an affected device through the web services interface, potentially exposing confidential information. The issue is limited to specific AnyConnect and WebVPN configurations and has been associated with ransomware activity, making prompt assessment and remediation important for teams running these platforms.

Because ASA and FTD devices often sit at network edges and handle remote access, any memory disclosure can reveal credentials, session data, or other sensitive material that attackers can reuse. Confirm all version and configuration details against the official Cisco advisory before acting.

How it works

The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). It stems from a buffer-tracking issue that occurs when the software parses invalid URLs requested against the web services interface. An unauthenticated or lightly authenticated attacker who can reach the affected interface can craft such requests to cause the device to return portions of memory. Those memory contents may include confidential data that was never intended to leave the appliance.

No public exploit code or precise request format is described here; the exact mechanics must be confirmed in the vendor advisory. The practical result is straightforward: successful abuse yields information that can aid further compromise, lateral movement, or credential theft. Because the flaw is tied to AnyConnect and WebVPN web services, only devices with those features enabled in vulnerable configurations are in scope.

Am I affected? How to find it in your systems

Cisco ASA and FTD appliances commonly serve as firewalls, VPN gateways, and remote-access concentrators. Inventory every ASA and FTD instance in your environment—physical, virtual, and cloud-hosted. Check whether AnyConnect or WebVPN services are enabled and exposed to untrusted networks. The vulnerability affects only specific configurations of those services; exact software releases and feature combinations must be verified against the Cisco advisory.

If you cannot confirm the precise software train or configuration, treat the device as potentially affected until the advisory is consulted.

How to remediate

The primary remediation is to apply the vendor-supplied software update that addresses CVE-2020-3259. Follow Cisco’s published instructions for the specific ASA or FTD release you run; the CISA-required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the official update can be applied, reduce exposure with compensating controls. Segment the ASA or FTD management and VPN interfaces so they are reachable only from authorized jump hosts or internal networks. If a web application firewall or reverse-proxy sits in front of the web services interface, consider temporary virtual-patching rules that drop or sanitize malformed URL requests; test thoroughly to avoid breaking legitimate AnyConnect or WebVPN traffic.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been used in ransomware campaigns. Memory disclosure can leak credentials or session material that later enables broader compromise. If you suspect the device was reachable and unpatched during the period of known exploitation, treat any sensitive data that may have resided in memory as potentially exposed. Rotate credentials, review VPN session logs, and investigate for follow-on activity. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
WeaknessCWE-200
Added to CISA KEVFeb 15, 2024
Federal patch deadlineMar 7, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities