CVE-2020-3187
published 2020-05-06CVE-2020-3187: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…
PriorityP191critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
96.59%
99.9th percentile
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.37 | 9.10.1.37 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.3.2 | 9.12.3.2 |
| cisco | adaptive_security_appliance_software | >= 9.13 < 9.13.1.7 | 9.13.1.7 |
| cisco | adaptive_security_appliance_software | >= 9.6 < 9.6.4.40 | 9.6.4.40 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.4.15 | 9.8.4.15 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.66 | 9.9.2.66 |
| cisco | asa_5505_firmware | — | — |
| cisco | asa_5510_firmware | — | — |
| cisco | asa_5512-x_firmware | — | — |
| cisco | asa_5515-x_firmware | — | — |
| cisco | asa_5520_firmware | — | — |
| cisco | asa_5525-x_firmware | — | — |
| cisco | asa_5540_firmware | — | — |
| cisco | asa_5545-x_firmware | — | — |
| cisco | asa_5550_firmware | — | — |
| cisco | asa_5555-x_firmware | — | — |
| cisco | asa_5580_firmware | — | — |
| cisco | asa_5585-x_firmware | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | firepower_threat_defense | >= 6.2.3 < 6.2.3.16 | 6.2.3.16 |
| cisco | firepower_threat_defense | >= 6.3.0 < 6.3.0.6 | 6.3.0.6 |
| cisco | firepower_threat_defense | >= 6.4.0 < 6.4.0.8 | 6.4.0.8 |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.5.0.4 | 6.5.0.4 |
Detection & IOCsextracted from sources · hover to see the quote
path/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua↗
- →Detect exploitation attempts by inspecting HTTP Cookie headers for directory traversal sequences targeting the +CSCOU+ path, specifically the pattern 'token=..//+CSCOU+/' ↗
- →Monitor HTTP GET requests to /+CSCOE+/session_password.html combined with a Cookie header containing traversal sequences as an indicator of CVE-2020-3187 exploitation
- →Detect vulnerable Cisco ASA/FTD WebVPN endpoints by checking HTTP response headers for the presence of 'webvpn' or 'Webvpn' strings
- →Active scanning for CVE-2020-3187 was observed in the wild; GreyNoise released a dedicated scanner tag on 2023-09-20 indicating ongoing mass exploitation attempts ↗
- →The vulnerability is only exploitable when WebVPN or AnyConnect features are enabled; scope detection to devices with these features active ↗
- →Use Google dork 'inurl:/+CSCOE+/' to identify exposed Cisco ASA WebVPN panels that may be targeted by this vulnerability ↗
- ·Exploitation requires WebVPN or AnyConnect to be configured on the device; the vulnerability does not exist on devices without these features enabled ↗
- ·Files deleted via exploitation are restored upon device reload; the impact is temporary unless the attacker leverages read access for credential/config theft ↗
- ·The attacker's file access is limited to the web services file system only; ASA/FTD system files and underlying OS files are not accessible via this vulnerability ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.1CRITICAL
vendor_cisco9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
vendor_cisco·2020-05-06·CVSS 9.1
CVE-2020-3187 [CRITICAL] CWE-22 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system.
The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulner
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3187 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
CVE-2020-3187: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation o
GHSA
GHSA-5f48-6vm9-w28v: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
ghsa_unreviewed·2022-05-24
CVE-2020-3187 [HIGH] CWE-22 GHSA-5f48-6vm9-w28v: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file s
VulnCheck
Cisco firepower_threat_defense Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2020·CVSS 9.1
CVE-2020-3187 [CRITICAL] Cisco firepower_threat_defense Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Cisco firepower_threat_defense Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any f
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005168; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005166; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
exploitdb·2020-07-29·CVSS 9.1
CVE-2020-3187 [CRITICAL] Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
---
# Exploit Title: Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
# Google Dork: inurl:/+CSCOE+/
# Date: 2020-08-27
# Exploit Author: 0xmmnbassel
# Vendor Homepage: https://www.cisco.com/c/en/us/products/security/asa-firepower-services/index.html#~models
# Version: Cisco ASA Software >=9.14 except 9.11 Cisco FTD Software >=6.2.2 and 6.2.3,6.3.0,6.4.0,6.50,6.60
# Vulnerability Type: unauthenticated file deletion
# Version: Cisco ASA Software releases 9.5 and earlier, as well as
# Release 9.7, have reached end of software maintenance. Customers are
# advised to migrate to a supported release that includes the fix for
# this vulnerability.
# CVE : CVE-2020-318
Nuclei
Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
nuclei·CVSS 9.1
CVE-2020-3187 [CRITICAL] Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software are susceptible to directory traversal vulnerabilities that could allow an unauthenticated, remote attacker to obtain read and delete access to sensitive files on a targeted system.
Template:
id: CVE-2020-3187
info:
name: Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
author: KareemSe1im
severity: critical
description: Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software are susceptible to directory traversal vulnerabilities that could allow an unauthenticated, remote attacker to obtain read and delet
Nuclei
Cisco ASA Security Checks
nuclei·CVSS 7.5
CVE-2020-3187 [HIGH] Cisco ASA Security Checks
Cisco ASA Security Checks
A simple workflow that runs all Cisco ASA related nuclei templates on a given target.
Template:
id: cisco-asa-workflow
info:
name: Cisco ASA Security Checks
author: flag007
description: A simple workflow that runs all Cisco ASA related nuclei templates on a given target.
workflows:
- template: http/exposed-panels/cisco/cisco-asa-panel.yaml
subtemplates:
- template: http/cves/2020/CVE-2020-3187.yaml
- template: http/cves/2020/CVE-2020-3452.yaml
- template: http/cves/2018/CVE-2018-0296.yaml
HackerOne
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
hackerone·2022-05-12·CVSS 9.1
CVE-2020-3187 [CRITICAL] CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences.
The IP has a SSL certificate pointing to .█████
curl -kv https://█████████/
output
```
Server certificate:
* subject: █████████.mil
```
## Impact
An exploit could allow the attacker to view or delete arbitrary files on
HackerOne
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
hackerone·2022-05-12·CVSS 9.1
CVE-2020-3187 [CRITICAL] CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences.
The IP has a SSL certificate pointing to ████████
curl -kv https://███
output:
```
Server certificate:
████
```
## Impact
An exploit could allow the attacker to view or delete arbitrary files on the targeted system. Whe
HackerOne
Arbitrary File Deletion (CVE-2020-3187) on ████████
hackerone·2022-03-18·CVSS 9.1
CVE-2020-3187 [CRITICAL] Arbitrary File Deletion (CVE-2020-3187) on ████████
Arbitrary File Deletion (CVE-2020-3187) on ████████
Hello team,
I hope you're doing well, healthy & wealthy.
I found an Arbitrary File Deletion (CVE-2020-3187) vulnerability on https://██████████/+CSCOE+/session_password.html that allows the Arbitrary File Deletion.
## References
- https://twitter.com/aboul3la/status/1286809567989575685
- http://packetstormsecurity.com/files/158648/Cisco-Adaptive-Security-Appliance-Software-9.7-Arbitrary-File-Deletion.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-path-JE3azWw43
Arbitrary File Deletion Reference:
- https://video.twimg.com/ext_tw_video/1286808440271183873/pu/vid/1270x720/8tccA2VgHV9TDtW4.mp4
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
cvss-score: 9.10
cve-id:
HackerOne
Unauthenticated Arbitrary File Deletion (CVE-2020-3187)
hackerone·2021-08-29·CVSS 9.1
CVE-2020-3187 [CRITICAL] Unauthenticated Arbitrary File Deletion (CVE-2020-3187)
Unauthenticated Arbitrary File Deletion (CVE-2020-3187)
## Summary:
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences.
## Vulnerable Endpoint:
```
https://129.0.176.5/+CSCOE+/session_password.html
```
## Steps To Reproduce:
1. First I performed a curl request to validate that /session_password.html gave a 200 response.
2. E
HackerOne
Unauthenticated Arbitrary File Deletion "CVE-2020-3187" in █████
hackerone·2020-11-23·CVSS 9.1
CVE-2020-3187 [CRITICAL] Unauthenticated Arbitrary File Deletion "CVE-2020-3187" in █████
Unauthenticated Arbitrary File Deletion "CVE-2020-3187" in █████
**Summary:**
A vulnerability in the interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files.
**Description:**
Vulnerable host:
`██████████`
## Impact
An exploit could allow the attacker to view or delete arbitrary files on the system.
## Step-by-step Reproduction Instructions
1.Identifying vulnerable host by send request to /+CSCOE+/session_password.html.
curl -skiL "███/+CSCOE+/session_password.html"
```
GET /+CSCOE+/session_password.html HTTP/1.1
Host: ███████
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0
HackerOne
https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD
hackerone·2020-11-23·CVSS 9.1
CVE-2020-3187 [CRITICAL] https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD
https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD
Hi @U.S. Dept Of Defense, I found a host which is running on the web services interface of Cisco ASA/FTD and it is vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after the exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system.
**Proof of Concept:**
Now we know that in CVE-2020-3187 - Unauthentica
HackerOne
https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD
hackerone·2020-10-16·CVSS 9.1
CVE-2020-3187 [CRITICAL] https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD
https://██████ vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD
Hi team , while testing i found a host ip https://█████████ which belong to DoD (██████████.mil) running web services interface of Cisco ASA/FTD and it is vulnerable to CVE-2020-3187 - Unauthenticated arbitrary file deletion in Cisco ASA/FTD. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system.
Vulnerable IP : https://█████████
i
HackerOne
Unauthenticated Arbitrary File Deletion ("CVE-2020-3187") in ████████
hackerone·2020-09-29·CVSS 9.1
CVE-2020-3187 [CRITICAL] Unauthenticated Arbitrary File Deletion ("CVE-2020-3187") in ████████
Unauthenticated Arbitrary File Deletion ("CVE-2020-3187") in ████████
**Description:**
A vulnerability in the interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files.
Vulnerable host:
- `https://██████/`
## Impact
An exploit could allow the attacker to view or delete arbitrary files on the system.
## Step-by-step Reproduction Instructions
1) Identifying vulnerable host by send request to `/+CSCOE+/session_password.html`.
```bash
> curl -skiL "https://██████/+CSCOE+/session_password.html"
```
```
GET /+CSCOE+/session_password.html HTTP/1.1
Host: ███████
User-Agent: curl/7.47.0
Accept: */*
HackerOne
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
hackerone·2020-09-21·CVSS 9.1
CVE-2020-3187 [CRITICAL] CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187 - Unauthenticated Arbitrary File Deletion
**Summary:**
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences.
## Vulnerable Endpoint
https://██████/+CSCOE+/session_password.html
## Impact
An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after
Tenable
Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
blogs_tenable·2020-05-07·CVSS 9.1
[CRITICAL] Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/158648/Cisco-Adaptive-Security-Appliance-Software-9.7-Arbitrary-File-Deletion.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-path-JE3azWw43http://packetstormsecurity.com/files/158648/Cisco-Adaptive-Security-Appliance-Software-9.7-Arbitrary-File-Deletion.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-path-JE3azWw43
2020-05-06
Published
Exploited in the wild