Path traversal in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2020-3187
Published: May 7, 2020 / Updated: May 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the web services interface. A remote attacker can send a specially crafted HTTP request and read or delete arbitrary files on the targeted system.
Affected software
Cisco Firewall Threat Defense (FTD)
How to mitigate CVE-2020-3187
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.8, 6.5.0.4
Links to Public Exploits and PoC-codes
- Exploit #9835 - CVE-2020-3187 (Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal) (May 23, 2024)
- Exploit #8914 - CVE-2020-3187-Scanlist (Batch scanning site.) (March 15, 2023)
- Exploit #7547 - CVE-2020-3187 () (March 30, 2022)
- Exploit #6479 - CVE-Vulnerability-POC (A collection of custom exploit scripts to determine the existence of CVE vulnerabilities. ) (June 29, 2021)
- Exploit #5688 - Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion (June 17, 2021)
- Exploit #5562 - CVE-2020-3187 () (June 14, 2021)
- Exploit #5349 - CVE-2020-3187 () (May 9, 2021)
- Exploit #4586 - CVE-2020-3187 () (September 11, 2020)
- Exploit #3625 - CVE-2020-3187 () (July 29, 2020)