CVE-2026-20070

MEDIUM

Cisco Secure Firewall ASA and FTD - Unauthenticated Cross-Site Scripting via VPN Web Services

Title source: llm
STIX 2.1

Description

A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device.  This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by persuading a user to follow a link to a malicious website that is designed to submit malicious input to the affected application. A successful exploit could allow the attacker to execute arbitrary HTML or script code in the browser in the context of the VPN web server.

Scores

CVSS v3 6.1
EPSS 0.0026
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80
Status published
Products (50)
cisco/adaptive_security_appliance_software 9.12.1
cisco/adaptive_security_appliance_software 9.12.1.2
cisco/adaptive_security_appliance_software 9.12.1.3
cisco/adaptive_security_appliance_software 9.12.2
cisco/adaptive_security_appliance_software 9.12.2.1
cisco/adaptive_security_appliance_software 9.12.2.4
cisco/adaptive_security_appliance_software 9.12.2.5
cisco/adaptive_security_appliance_software 9.12.2.9
cisco/adaptive_security_appliance_software 9.12.3
cisco/adaptive_security_appliance_software 9.12.3.2
... and 40 more
Published Mar 04, 2026
Tracked Since Mar 05, 2026