Junglewise Threat Intelligence

CVE-2020-3452: Cisco ASA and FTD Read-Only Path Traversal Vulnerability

CVE-2020-3452 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Cisco Adaptive Security Appliance (ASA) Software, Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD). Vendors: Cisco.

Executive brief

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software contain an improper input validation vulnerability in their web services interface. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests with directory traversal sequences to read sensitive files within the web services file system. This vulnerability specifically affects devices configured with WebVPN or AnyConnect features.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Firepower Threat Defense (FTD) Software

Timeline

  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: Publication date of the advisory.
  • exploited: Reported as exploited in the wild.

Related threats