Executive brief
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software contain an improper input validation vulnerability in their web services interface. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests with directory traversal sequences to read sensitive files within the web services file system. This vulnerability specifically affects devices configured with WebVPN or AnyConnect features.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software
- Cisco Firepower Threat Defense (FTD) Software
Timeline
- 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: Publication date of the advisory.
- exploited: Reported as exploited in the wild.