QID 317005
Date Published: 2021-08-23
QID 317005: Cisco Firepower Threat Defense Software WebVPN Cross-Site Scripting Vulnerability(cisco-sa-20191002-asa-xss)
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Firepower Threat Defense (FTD) Software
could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against
a user of the web-based management interface of an affected device.
Affected Products
Cisco FTD Software when configured for WebVPN.
Earlier than 6.2.3.15
From 6.3.0 Prior to 6.3.0.5
From 6.4.0 Prior to 6.4.0.6
Note: Practice check as cannot confirm whether configured for webvpn.
QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco FTD in the response of "version" command.
A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or
allow the attacker to access sensitive browser-based information.
Customers are advised to refer to cisco-sa-20191002-asa-xss for more information.
- cisco-sa-20191002-asa-xss -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-xss
CVEs related to QID 317005
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20191002-asa-xss |
|