CVSS 3.1 Score 6.1 of 10 (medium)


Published Nov 1, 2023
Updated: Jan 25, 2024
CWE ID 601


CVE-2023-20264 is a vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. It could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user authenticating to a remote access VPN session. The vulnerability stems from insufficient validation of the login URL, which can be exploited by convincing a user to access a site controlled by the attacker. This would enable the attacker to modify the login URL and intercept a successful SAML assertion, potentially gaining unauthorized access to the protected network. The base severity rating for this vulnerability is medium, with low impacts on integrity and confidentiality. Remediation measures should include updating affected software versions with the appropriate security patches or upgrades provided by Cisco.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-20264 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options