LiveActive security incident?Get immediate response
CVE Record

CVE-2020-3312: Cisco Firepower Threat Defense Software Information Disclosure Vulnerability

A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive data.

MediumCVSS 5.8Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2020-3312 affects Cisco Firepower Threat Defense Software. A remote attacker who does not need credentials could send specially crafted traffic to an affected device and gain unauthorized read access to sensitive data. The issue is rated medium, but exposure matters because FTD often sits in security-critical network paths.

Executive priority

Prioritize validation on internet-facing or boundary FTD deployments. Treat as a moderate-risk security control issue: not confirmed actively exploited, but remote unauthenticated access to sensitive data on network security infrastructure can create business impact.

Technical view

The flaw is in FTD application policy configuration and is attributed to insufficient application identification. Cisco and CVE describe unauthenticated remote exploitation through crafted traffic against an affected device, with successful exploitation allowing unauthorized read access to sensitive data. The supplied bundle does not identify affected release ranges or fixed versions.

Likely exposure

Organizations using Cisco Firepower Threat Defense Software may be exposed if they run affected versions and allow attacker-controlled traffic to reach the device. The bundle lists the product but does not provide exact vulnerable releases, deployment modes, or configuration prerequisites.

Exploitation context

The source bundle supports remote, unauthenticated exploitability via crafted traffic. It does not cite known public exploitation, and KEV is false, so active exploitation is not established from the provided evidence.

Researcher notes

Evidence is limited to CVE and Cisco advisory metadata in the bundle. The CVSS vector shown is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N, while the description emphasizes read access to sensitive data; preserve that inconsistency in reporting.

Mitigation direction

  • Inventory all Cisco FTD deployments and versions.
  • Review Cisco advisory cisco-sa-ftd-infodis-kZxGtUJD for affected and fixed releases.
  • Apply Cisco-recommended fixed software or mitigation guidance where applicable.
  • Limit untrusted traffic paths to affected FTD devices where operationally feasible.
  • Monitor Cisco and vulnerability-management feeds for updated guidance.

Validation and detection

  • Confirm whether Cisco FTD is deployed in the environment.
  • Map each FTD appliance to software version and policy configuration.
  • Compare versions against Cisco advisory guidance.
  • Review logs for unusual crafted or denied traffic patterns.
  • Document remediation status and residual exposure per device.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-3312 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.8 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.8CVSS 3.0MediumCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

5.8Medium
CVSS 3.0 vector shape for CVE-2020-3312Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco Firepower Threat Defense Softwaren/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.