Record summary
A quick snapshot of what this page covers.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2020-3452
- Vendor/project
- Cisco
- Product
- Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
- Vulnerability name
- Cisco ASA and FTD Read-Only Path Traversal Vulnerability
- Date added
- 2021-11-03
- Due date
- 2022-05-03
- Known ransomware campaign use
- Unknown
Exploit context
What the vulnerability is about.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Source
Where this page information comes from.
Original source
Original source links
Open the public records and source datasets used for this page.
