CVE-2020-3187Critical· 9.1▾ AbyssalPoC availableA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 19.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
97%
Exploit-DB · 5 GitHub repos · Nuclei ×1 (last check)
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.
secure_firewall_threat_defense >= 6.2.3, < 6.2.3.16secure_firewall_threat_defense >= 6.3.0, < 6.3.0.6secure_firewall_threat_defense >= 6.4.0, < 6.4.0.8secure_firewall_threat_defense >= 6.5.0, < 6.5.0.4asa_5505_firmware = 9.6(4)asa_5510_firmware = 9.6(4)asa_5512-x_firmware = 9.6(4)asa_5515-x_firmware = 9.6(4)asa_5520_firmware = 9.6(4)asa_5525-x_firmware = 9.6(4)asa_5540_firmware = 9.6(4)asa_5545-x_firmware = 9.6(4)asa_5550_firmware = 9.6(4)asa_5555-x_firmware = 9.6(4)asa_5580_firmware = 9.6(4)asa_5585-x_firmware = 9.6(4)adaptive_security_appliance_software >= 9.6, < 9.6.4.40adaptive_security_appliance_software >= 9.8, < 9.8.4.15adaptive_security_appliance_software >= 9.9, < 9.9.2.66adaptive_security_appliance_software >= 9.10, < 9.10.1.37adaptive_security_appliance_software >= 9.12, < 9.12.3.2adaptive_security_appliance_software >= 9.13, < 9.13.1.7Upgrade past the affected range:
secure_firewall_threat_defense 6.5.0.4adaptive_security_appliance_software 9.13.1.7Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3452High· 7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…
CVE-2020-3365Medium· 4.3A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories
CVE-2020-3236Medium· 6.7A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files
CVE-2021-1256Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques
CVE-2020-3550High· 8.1A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories…
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …