← back
CVE-2020-3452

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability

CVSS 7.5 HIGHEPSS 100.0%● KEVCWE-20
In short

A flaw in Cisco ASA and FTD web services allows attackers to read files they shouldn't access by sending specially crafted web requests. This matters because sensitive information stored in the web service area could be exposed without needing to log in.

Technical detail

Path traversal vulnerability in HTTP request URL processing of Cisco ASA and FTD web services interface, exploitable remotely without authentication when WebVPN or AnyConnect is configured. Lack of input validation permits directory traversal sequences in HTTP requests, allowing attackers to access arbitrary files within the web services file system; impact limited to web service scope, not underlying system files.

Summary generated and translated by AI from the official description.
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
public PoCs found30
githubgithub.com/darklotuskdb/CISCO-CVE-2020-3452-Scanner-Exploiter99githubgithub.com/cygenta/CVE-2020-345226githubgithub.com/PR3R00T/CVE-2020-3452-Cisco-Scanner25githubgithub.com/3ndG4me/CVE-2020-3452-Exploit24githubgithub.com/0x5ECF4ULT/CVE-2020-345224githubgithub.com/murataydemir/CVE-2020-34527githubgithub.com/fuzzlove/Cisco-ASA-FTD-Web-Services-Traversal6githubgithub.com/grim3/CVE-2020-34524githubgithub.com/foulenzer/CVE-2020-34523githubgithub.com/faisalfs10x/Cisco-CVE-2020-3452-shodan-scanner2githubgithub.com/XDev05/CVE-2020-3452-PoC2githubgithub.com/Loneyers/cve-2020-34522githubgithub.com/Cappricio-Securities/CVE-2020-34521githubgithub.com/paran0id34/CVE-2020-34521githubgithub.com/ludy-dev/Cisco-ASA-LFI1githubgithub.com/Aviksaikat/CVE-2020-34521githubgithub.com/mr-r3b00t/CVE-2020-34520githubgithub.com/Gh0st0ne/http-vuln-cve2020-3452.nse0githubgithub.com/sujaygr8/CVE-2020-34520githubgithub.com/Veids/CVE-2020-3452_auto0githubgithub.com/iveresk/cve-2020-34520githubgithub.com/abrewer251/CVE-2020-3452_Cisco_ASA_PathTraversal0githubgithub.com/curtishoughton/CVE-2020-3452-Cisco-Python-Scanner0exploitdbwww.exploit-db.com/exploits/48722unverifiedcve_referencepacketstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.htmlunverifiedcve_referencepacketstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.htmlunverifiedcve_referencepacketstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.htmlunverifiedexploitdbwww.exploit-db.com/exploits/49262unverifiedcve_referencepacketstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.htmlunverifiedexploitdbwww.exploit-db.com/exploits/48871unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →