Cisco disclosed a directory traversal vulnerability, CVE-2020-3452, affecting the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. The flaw stems from improper input validation of URLs in HTTP requests and allows an unauthenticated remote attacker to send crafted requests containing traversal sequences to read sensitive files from the device's web services file system.
The issue is exploitable when WebVPN or AnyConnect features are configured on affected devices. Reporting indicates the vulnerability does not provide access to ASA or FTD system files or to the underlying operating system, but it can still expose sensitive information stored within the web services environment, creating a significant risk for organizations using these remote access services.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
Cisco published a security advisory for CVE-2020-3452, an unauthenticated directory traversal vulnerability in the web services interface of Cisco ASA and Firepower Threat Defense software. The flaw allows remote attackers to read sensitive files from the web services file system on affected devices when WebVPN or AnyConnect is configured.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.