Answer in brief
CVE-2020-3259 records a High severity (CVSS 7.5) vulnerability in Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability. The current sources mark it as known exploited. The current feed maps cisco/adaptive_security_appliance_software (generic), cisco/adaptive_security_appliance_software (generic), cisco/adaptive_security_appliance_software (generic), cisco/adaptive_security_appliance_software (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps cisco/adaptive_security_appliance_software (generic), cisco/adaptive_security_appliance_software (generic), cisco/adaptive_security_appliance_software (generic), cisco/adaptive_security_appliance_software (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| cisco/adaptive_security_appliance_softwaregeneric | >=9.12 <9.12.3.9 | 9.12.3.9 |
| cisco/adaptive_security_appliance_softwaregeneric | >=9.13 <9.13.1.10 | 9.13.1.10 |
| cisco/adaptive_security_appliance_softwaregeneric | >=9.8 <9.8.4.20 | 9.8.4.20 |
| cisco/adaptive_security_appliance_softwaregeneric | >=9.9 <9.9.2..67 | 9.9.2..67 |
| cisco/adaptive_security_appliance_softwaregeneric | >=9.10 <9.10.1.40 | 9.10.1.40 |
| Cisco/Cisco Adaptive Security Appliance (ASA) Softwaregeneric | n/a | Not reported |
| cisco/firepower_threat_defensegeneric | >=6.4.0 <6.4.0.9 | 6.4.0.9 |
| cisco/firepower_threat_defensegeneric | >=6.5.0 <6.5.0.5 | 6.5.0.5 |
| cisco/firepower_threat_defensegeneric | >=6.2.3 <6.2.3.16 | 6.2.3.16 |
| cisco/firepower_threat_defensegeneric | >=6.3.0 <6.3.0.6 | 6.3.0.6 |
Published upstream
May 6, 2020
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Feb 15, 2024
Evidence: source:kev:kev:kev:recordA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
Quoted source text, attributed separately from HOL analysis.