VDB

CISCO-SA-ASAFTD-SAML-LKTTRWZP

CISCO-SA-ASAFTD-SAML-LKTTRWZP PUBLISHED CVSS 6.099999904632568 MEDIUM

A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information. This vulnerability is due to insufficient input validation of multiple HTTP parameters. An attacker could exploit this vulnerability by persuading a user to access a malicious link. A successful exploit could allow the attacker to conduct a reflected XSS attack through an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75736"].

Risk Scores

CVSS v3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
9.16.2.14
9.16.3.23
9.16.4.19
9.16.2.11
9.16.4.9
9.16.3
9.16.1.28
9.16.3.14
9.16.2.13
9.16.2.7
9.16.1
9.16.3.15
9.16.4
9.16.3.3
9.16.3.19
9.16.4.38
9.16.4.27
9.16.2
9.16.4.14
9.16.2.3

Timeline

  • Mar 4, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›