cbcvebase.
CVE-2020-3187
published 2020-05-06

CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…

PriorityP191critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
96.59%
99.9th percentile
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.

Affected

24 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software>= 9.10 < 9.10.1.379.10.1.37
ciscoadaptive_security_appliance_software>= 9.12 < 9.12.3.29.12.3.2
ciscoadaptive_security_appliance_software>= 9.13 < 9.13.1.79.13.1.7
ciscoadaptive_security_appliance_software>= 9.6 < 9.6.4.409.6.4.40
ciscoadaptive_security_appliance_software>= 9.8 < 9.8.4.159.8.4.15
ciscoadaptive_security_appliance_software>= 9.9 < 9.9.2.669.9.2.66
ciscoasa_5505_firmware
ciscoasa_5510_firmware
ciscoasa_5512-x_firmware
ciscoasa_5515-x_firmware
ciscoasa_5520_firmware
ciscoasa_5525-x_firmware
ciscoasa_5540_firmware
ciscoasa_5545-x_firmware
ciscoasa_5550_firmware
ciscoasa_5555-x_firmware
ciscoasa_5580_firmware
ciscoasa_5585-x_firmware
ciscocisco_adaptive_security_appliance_software
ciscofirepower_threat_defense>= 6.2.3 < 6.2.3.166.2.3.16
ciscofirepower_threat_defense>= 6.3.0 < 6.3.0.66.3.0.6
ciscofirepower_threat_defense>= 6.4.0 < 6.4.0.86.4.0.8
ciscofirepower_threat_defense>= 6.5.0 < 6.5.0.46.5.0.4

Detection & IOCsextracted from sources · hover to see the quote

path/+CSCOE+/session_password.html
path/+CSCOU+/
path/+CSCOE+/
cookietoken=..//+CSCOU+/<file>
path/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
path%2bCSCOE%2b/portal_inc.lua
  • Detect exploitation attempts by inspecting HTTP Cookie headers for directory traversal sequences targeting the +CSCOU+ path, specifically the pattern 'token=..//+CSCOU+/'
  • Monitor HTTP GET requests to /+CSCOE+/session_password.html combined with a Cookie header containing traversal sequences as an indicator of CVE-2020-3187 exploitation
  • Detect vulnerable Cisco ASA/FTD WebVPN endpoints by checking HTTP response headers for the presence of 'webvpn' or 'Webvpn' strings
  • Active scanning for CVE-2020-3187 was observed in the wild; GreyNoise released a dedicated scanner tag on 2023-09-20 indicating ongoing mass exploitation attempts
  • The vulnerability is only exploitable when WebVPN or AnyConnect features are enabled; scope detection to devices with these features active
  • Use Google dork 'inurl:/+CSCOE+/' to identify exposed Cisco ASA WebVPN panels that may be targeted by this vulnerability
  • ·Exploitation requires WebVPN or AnyConnect to be configured on the device; the vulnerability does not exist on devices without these features enabled
  • ·Files deleted via exploitation are restored upon device reload; the impact is temporary unless the attacker leverages read access for credential/config theft
  • ·The attacker's file access is limited to the web services file system only; ASA/FTD system files and underlying OS files are not accessible via this vulnerability

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.1CRITICAL
vendor_cisco9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.