cve-2020-3452
HIGH CVSS 7.5 cisa_known_exploited
Description
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Timeline
- Published
- 2021-11-03
- Last Modified
- 2021-11-03
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 7.5,
"datePublished": "2021-11-03",
"dateUpdated": "2021-11-03",
"description": "Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.",
"dueDate": "2022-05-03",
"id": "CVE-2020-3452",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-3452",
"product": "Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "HIGH",
"source": "cisa_known_exploited",
"title": "Cisco ASA and FTD Read-Only Path Traversal Vulnerability",
"vendor": "Cisco"
}
Enrichment data
Aggregated bundle (all enrichments)