🛡 CVE-2020-3259
Cisco ASA and FTD Information Disclosure Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) CWE-200
Ransomware use
KNOWN
CISA KEV
EPSS
69.3%
Likely exploited · 99th pct
Added to KEV
2024-02-15
CISA
Remediate by
2024-03-07
⚠ OVERDUE
CWE
CWE-200
weakness
📈 EPSS exploit probability
69.3%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 99% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2024-03-07. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential
🏹 Attributed exploitation
Malware / ransomware (KEV): ransomware (KEV-flagged)
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron