Path traversal in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2020-3452
Published: July 24, 2020 / Updated: March 7, 2025
Vulnerability identifier: #VU31817
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3452
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the web services interface. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
IBM Transformation Extender Advanced
Cisco Firewall Threat Defense (FTD)
IBM Transformation Extender Advanced
How to mitigate CVE-2020-3452
Install update from vendor's website.
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.6.4.42, 9.8.4.20, 9.9.2.74, 9.10.1.42, 9.12.3.12, 9.13.1.10, 9.14.1.10
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.2.3.16, 6.6.0.1
IBM Transformation Extender Advanced - update to 10.0.1.8
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.2.3.16, 6.6.0.1
IBM Transformation Extender Advanced - update to 10.0.1.8
Links to Public Exploits and PoC-codes
- Exploit #11197 - CVE (CVE exploits) (March 7, 2025)
- Exploit #9572 - CVE-2020-3452 (Exploitation Scanner CVE-2020-3452 to enumerate the standard files accessible in the Path Traversal of CISCO ASA/FTD .?) (February 27, 2024)
- Exploit #7720 - cve-2020-3452 (Just proof of concept for Cisco CVE-2020-3452. Using external or internal file base.) (May 8, 2022)
- Exploit #7229 - CVE-2020-3452_auto () (January 10, 2022)
- Exploit #6986 - CVE-2020-3452 (Test vulnerability of CVE-2020-3452) (November 3, 2021)
- Exploit #6480 - CVE-Vulnerability-POC (A collection of custom exploit scripts to determine the existence of CVE vulnerabilities. ) (June 29, 2021)
- Exploit #5687 - Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion (June 17, 2021)
- Exploit #5689 - Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion (June 17, 2021)
- Exploit #5630 - Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2) (June 17, 2021)
- Exploit #5548 - CVE-2020-3452 () (June 10, 2021)
- Exploit #5136 - Cisco-CVE-2020-3452-shodan-scanner (simple bash script of CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability checker ) (February 9, 2021)
- Exploit #5119 - Cisco-CVE-2020-3452-checker (simple bash script of Cisco CVE-2020-3452 checker ) (February 4, 2021)
- Exploit #5117 - Cisco-ASA-FTD-Web-Services-Traversal (CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) traversal) (February 4, 2021)
- Exploit #4997 - CISCO-CVE-2020-3452-Scanner-Exploiter (CISCO CVE-2020-3452 Scanner & Exploiter) (January 5, 2021)
- Exploit #4941 - CVE-2020-3452 () (December 16, 2020)
- Exploit #4869 - CVE-2020-3452 (CVE-2020-3452) (November 21, 2020)
- Exploit #4706 - CVE-2020-3452-Exploit (Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.) (October 14, 2020)
- Exploit #4697 - CVE_2020_3452_Detect () (October 14, 2020)
- Exploit #4695 - Cisco ASA and FTD 9.6.4.42 - Path Traversal (October 13, 2020)
- Exploit #4662 - CVE-2020-3452-Scanner (Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.) (September 28, 2020)
- Exploit #4596 - CVE-2020-3452 (CVE-2020-3452 exploit) (September 11, 2020)
- Exploit #4561 - CVE-2020-3452 (CVE-2020-3452 - directory traversal in Cisco ASA and Cisco Firepower Threat Defense) (September 1, 2020)
- Exploit #4529 - CVE-2020-3452 ([CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal) (September 1, 2020)
- Exploit #4527 - CVE-2020-3452 (CVE-2020-3452 exploit) (September 1, 2020)
- Exploit #4524 - Path traversal (September 1, 2020)
- Exploit #3672 - http-vuln-cve2020-3452.nse (CVE-2020-3452 : Cisco ASA and FTD Unauthorized Remote File Reading Nmap NSE Script) (July 30, 2020)
- Exploit #3624 - checker-cve2020-3452 (Cisco Adaptive Security Appliance and FTD Unauthorized Remote File Reading) (July 29, 2020)
- Exploit #3590 - CVE-2020-3452 (Little, stupid python validator(?) for CVE-2020-3452 on CISCO devices.) (July 25, 2020)
- Exploit #3599 - CVE-2020-3452-PoC () (July 25, 2020)
- Exploit #3598 - cve-2020-3452 (unauth file read in cisco asa & firepower.) (July 25, 2020)
- Exploit #3596 - CVE-2020-3452-Cisco-Scanner (CVE-2020-3452 Cisco ASA Scanner -unauth Path Traversal Check) (July 25, 2020)
- Exploit #3595 - CVE-2020-3452 () (July 25, 2020)
- Exploit #3591 - cve-2020-3452 () (July 25, 2020)