Path traversal in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2020-3452

 

Path traversal in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2020-3452

Published: July 24, 2020 / Updated: March 7, 2025


Vulnerability identifier: #VU31817
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3452
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the web services interface. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
IBM Transformation Extender Advanced

How to mitigate CVE-2020-3452

Install update from vendor's website.

Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.6.4.42, 9.8.4.20, 9.9.2.74, 9.10.1.42, 9.12.3.12, 9.13.1.10, 9.14.1.10
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.2.3.16, 6.6.0.1
IBM Transformation Extender Advanced - update to 10.0.1.8

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins