CVE-2020-3452Cisco ASA and FTD Read-Only Path Traversal Vulnerability

PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2020-3452
项目:
Cisco
产品:
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
添加日期:
2021-11-03
到期日:
2022-05-03
最后更新:
June 21, 2025

漏洞名称

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

描述

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

已知用于勒索软件活动吗?

勒索软件状态:
Unknown

采集行动

Apply updates per vendor instructions.

其他说明

相关 CWE