Skip to content
COOEY

EXPOSURES › CVE-2020-3452

CVE-2020-3452

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3452 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Cisco ASA and FTD devices suffered a path traversal flaw allowing attackers to read arbitrary files via crafted HTTP requests.

The vulnerability stems from improper input validation in HTTP URL processing, enabling file disclosure on the device's web services filesystem. DIB organizations must urgently patch this unpatched CVE, as it represents a known, avoidable exposure that could lead to further compromise if attackers leverage the exposed data.

Shame score — A known, unpatched vulnerability in a critical network security device that was actively exploited in the wild, demonstrating a failure to maintain a secure posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.60
Acknowledged vulnerability, potential for significant impact.
cooey ↗ negative -0.70
Describes the vulnerability and potential impact.
"An attacker could exploit this vulnerability…arbitrary files within the web services file system."
AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized