CVE-2020-3452 is a directory traversal vulnerability in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software, specifically within their web services interface. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated, remote attacker to read sensitive files from the web services file system due to improper input validation in HTTP requests. While it cannot access core OS files, its ease of exploitation (low attack complexity, no user interaction) makes it critical. This CVE is actively exploited in the wild, with multiple public exploit codes available and significant community and media attention, indicating a high risk of compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.6, < 9.6.4.42CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.8, < 9.8.4.20CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.9, < 9.9.2.74CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.10, < 9.10.1.42CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.12, < 9.12.3.12CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.