Impact
The vulnerability results from improper neutralization of user‑supplied input in Cisco's Secure Firewall products, identified as CWE‑707. This weakness can allow malicious content to be inserted into responses that are then rendered by the device's web interface, potentially enabling unauthorized actions when a user views the content. The description does not specify the exact payload types, but it indicates a flaw that could be exploited if neutralization is bypassed. The impact is limited to the context of the web interface and does not directly imply compromise of the underlying operating system or firmware.
Affected Systems
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC). Any firmware or software version installed before the hardening release is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.9 highlights high severity, while the EPSS score of less than 1% suggests that this flaw is not frequently exploited in the wild. The vulnerability is not listed in CISA's KEV catalog. Based on the nature of the flaw, the likely attack vector involves the web management interface of an ASA, FTD, or FMC device, where an attacker could submit crafted input that bypasses neutralization controls. Successful exploitation could enable script execution or other unauthorized actions within the context of the authenticated user or the device itself.
OpenCVE Enrichment