CVE-2020-3452

HIGH KEV NUCLEI

Cisco ASA/FTD - Path Traversal

Title source: llm

Description

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.

Exploits (28)

exploitdb WORKING POC
by Freakyclown · pythonwebappshardware
https://www.exploit-db.com/exploits/49262
exploitdb WORKING POC
by 3ndG4me · textwebappshardware
https://www.exploit-db.com/exploits/48871
exploitdb WORKING POC
by 0xmmnbassel · textwebappshardware
https://www.exploit-db.com/exploits/48722
nomisec WORKING POC 99 stars
by darklotuskdb · infoleak
https://github.com/darklotuskdb/CISCO-CVE-2020-3452-Scanner-Exploiter
nomisec WORKING POC 26 stars
by cygenta · infoleak
https://github.com/cygenta/CVE-2020-3452
nomisec SCANNER 25 stars
by PR3R00T · infoleak
https://github.com/PR3R00T/CVE-2020-3452-Cisco-Scanner
nomisec WORKING POC 24 stars
by 3ndG4me · infoleak
https://github.com/3ndG4me/CVE-2020-3452-Exploit
nomisec WORKING POC 24 stars
by 0x5ECF4ULT · infoleak
https://github.com/0x5ECF4ULT/CVE-2020-3452
nomisec WORKING POC 7 stars
by murataydemir · infoleak
https://github.com/murataydemir/CVE-2020-3452
nomisec WORKING POC 6 stars
by fuzzlove · infoleak
https://github.com/fuzzlove/Cisco-ASA-FTD-Web-Services-Traversal
nomisec SCANNER 4 stars
by grim3 · infoleak
https://github.com/grim3/CVE-2020-3452
nomisec SCANNER 3 stars
by foulenzer · remote-auth
https://github.com/foulenzer/CVE-2020-3452
nomisec SCANNER 2 stars
by faisalfs10x · infoleak
https://github.com/faisalfs10x/Cisco-CVE-2020-3452-shodan-scanner
nomisec WORKING POC 2 stars
by Loneyers · infoleak
https://github.com/Loneyers/cve-2020-3452
nomisec SCANNER 2 stars
by XDev05 · poc
https://github.com/XDev05/CVE-2020-3452-PoC
nomisec SCANNER 1 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2020-3452
nomisec SCANNER 1 stars
by Aviksaikat · infoleak
https://github.com/Aviksaikat/CVE-2020-3452
nomisec WORKING POC 1 stars
by paran0id34 · infoleak
https://github.com/paran0id34/CVE-2020-3452
nomisec WORKING POC 1 stars
by ludy-dev · infoleak
https://github.com/ludy-dev/Cisco-ASA-LFI
gitlab WORKING POC
by fuzzlove-group · poc
https://gitlab.com/fuzzlove-group/Cisco-ASA-FTD-Web-Services-Traversal
nomisec WORKING POC
by abrewer251 · infoleak
https://github.com/abrewer251/CVE-2020-3452_Cisco_ASA_PathTraversal
nomisec WORKING POC
by iveresk · infoleak
https://github.com/iveresk/cve-2020-3452
nomisec WORKING POC
by Veids · remote-auth
https://github.com/Veids/CVE-2020-3452_auto
nomisec NO CODE
by sujaygr8 · infoleak
https://github.com/sujaygr8/CVE-2020-3452
nomisec SCANNER
by Gh0st0ne · poc
https://github.com/Gh0st0ne/http-vuln-cve2020-3452.nse
nomisec WORKING POC
by mr-r3b00t · poc
https://github.com/mr-r3b00t/CVE-2020-3452
vulncheck_xdb SCANNER
infoleak
https://github.com/toy0756428/CVE_2020_3452_Detect
vulncheck_xdb SCANNER
infoleak
https://github.com/MrCl0wnLab/checker-cve2020-3452

Nuclei Templates (1)

Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
HIGHby pdteam

Scores

CVSS v3 7.5
EPSS 0.9445
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-24723
CWE
CWE-22 CWE-20
Status published
Products (2)
cisco/adaptive_security_appliance_software 9.6 - 9.6.4.42
cisco/firepower_threat_defense 6.2.3 - 6.2.3.16
Published Jul 22, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026