cve-2020-3452

HIGH CVSS 7.5 cisa_known_exploited
Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

Timeline
Published
2021-11-03
Last Modified
2021-11-03
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.5,
  "datePublished": "2021-11-03",
  "dateUpdated": "2021-11-03",
  "description": "Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs.  An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.",
  "dueDate": "2022-05-03",
  "id": "CVE-2020-3452",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-3452",
  "product": "Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)",
  "requiredAction": "Apply updates per vendor instructions.",
  "severity": "HIGH",
  "source": "cisa_known_exploited",
  "title": "Cisco ASA and FTD Read-Only Path Traversal Vulnerability",
  "vendor": "Cisco"
}
Enrichment data
View JSON API Download JSON