EXPOSURES › CVE-2020-3452
CVE-2020-3452
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA and FTD devices suffered a path traversal flaw allowing attackers to read arbitrary files via crafted HTTP requests.
The vulnerability stems from improper input validation in HTTP URL processing, enabling file disclosure on the device's web services filesystem. DIB organizations must urgently patch this unpatched CVE, as it represents a known, avoidable exposure that could lead to further compromise if attackers leverage the exposed data.
Shame score — A known, unpatched vulnerability in a critical network security device that was actively exploited in the wild, demonstrating a failure to maintain a secure posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
"An attacker could exploit this vulnerability…arbitrary files within the web services file system."
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |