LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-3452: Cisco ASA and FTD Read-Only Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-3452 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this…

CVE-2020-3452 is a path traversal weakness in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) that stems from improper input validation when those products process URLs in HTTP requests. An unauthenticated attacker who can reach the affected web services interface may send crafted requests containing directory traversal sequences and read arbitrary files from the device’s web services file system. Because ASA and FTD often sit at network perimeters and hold configuration, certificates, and other sensitive material, successful abuse can give an attacker reconnaissance that aids further compromise. Confirm exact affected releases and fixed images against the current Cisco advisory.

How it works

The underlying weakness is CWE-20 (Improper Input Validation). When the appliance handles certain HTTP requests, it does not adequately sanitize URL path components. An attacker supplies directory traversal character sequences (for example, sequences that resolve outside the intended web root) inside a crafted request aimed at the device’s web services. If the request is accepted, the appliance returns the contents of files that reside within the web services file system rather than rejecting the path. The CISA summary characterizes the impact as read-only access to arbitrary files in that file system; it does not describe remote code execution or write capability. Exact request format, required headers, or reachable paths are not detailed here and must be taken from the vendor advisory and any accompanying technical notes.

Am I affected? How to find it in your systems

Cisco ASA and FTD are commonly deployed as firewalls, VPN gateways, and threat-defense appliances at internet edges, in DMZs, and at site-to-site boundaries. Inventory every ASA and FTD instance, including virtual and hardware platforms, and record the running software image and any enabled web or management services that accept HTTP/HTTPS.

How to remediate

Patch first. Apply the software updates Cisco published for this vulnerability, following the vendor’s installation and reload guidance for ASA and FTD. CISA’s required action is to apply updates per vendor instructions; verify the advisory for the precise fixed releases that match your hardware and feature licenses.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection.

If your data may have been exposed

Actively exploited path-traversal flaws on perimeter devices can lead to disclosure of configuration files, certificates, or other material stored in the web services file system, which in turn can enable deeper intrusion. Known ransomware use of this CVE is not documented in the supplied facts, but any confirmed file read should be treated as a potential precursor to broader compromise. Rotate credentials and keys that may have resided on the device, review configuration integrity, and examine downstream systems for follow-on activity. You can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior incidents while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities