QID 150447
Date Published: 2022-01-17
QID 150447: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cross-Site Scripting (XSS) Vulnerabilities
Web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software running with a vulnerable AnyConnect or WebVPN configurations are affected by multiple Cross-site scripting (XSS) vulnerabilities.
Affected Products:
Cisco Adaptive Security Appliance (ASA)
Cisco Firepower Threat Defense (FTD)
QID Detection Logic :
This QID sends HTTP POST request to the vulnerable endpoint with a XSS payload and based on the response confirms if the target is vulnerable.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
Customers are advised to upgrade Cisco devices to latest version and refer to Cisco Security Advisory for more information.
- Cisco Security Advisory -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-multiple-FCB3vPZe
CVEs related to QID 150447
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asaftd-xss-multiple-FCB3vPZe |
|