PT-2020-2165 · Cisco · Cisco Ftd+1

Mikhail Klyuchnikov

·

Published

2020-05-06

·

Updated

2024-12-20

·

CVE-2020-3187

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description A vulnerability in the web services interface could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. This could allow the attacker to view or delete arbitrary files within the web services file system, which is enabled when the affected device is configured with either WebVPN or AnyConnect features. However, this vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02069
CVE-2020-3187

Affected Products

Cisco Asa
Cisco Ftd