CVE-2018-0296 is a vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software. The flaw is caused by improper input validation of the HTTP URL, enabling directory traversal through crafted requests. An unauthenticated remote attacker can exploit the issue over IPv4 or IPv6 HTTP traffic against exposed management interfaces. Depending on the affected software release, successful exploitation can either cause the device to reload unexpectedly, producing a denial-of-service condition, or allow unauthenticated access to sensitive system information through traversal of web-accessible resources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit auxiliary module (modules/auxiliary/scanner/http/cisco_directory_traversal.rb) targeting a directory traversal vulnerability (CVE-2018-0296) in Cisco ASA and FTD devices. The module exploits the vulnerability by sending crafted HTTP GET requests to the device's web VPN interface, allowing an unauthenticated attacker to enumerate files, directories, and currently logged-in users. The module is operational and provides information disclosure capabilities, but does not provide a shell or code execution. The main endpoints targeted are specific crafted paths that leverage the directory traversal flaw to access sensitive files and session information. The code is written in Ruby and is designed to be run within the Metasploit framework.
This repository contains a Python exploit script (cisco_asa.py) and a README.md for CVE-2018-0296, a path traversal vulnerability in Cisco ASA and Firepower Threat Defense (FTD) software. The exploit targets the web interface of vulnerable Cisco devices, allowing unauthenticated attackers to enumerate directory contents, files, active sessions, and usernames by sending crafted HTTP requests to specific endpoints. The script verifies the target is a Cisco ASA device, attempts to exploit the vulnerability, and saves the extracted information to a local text file. The README provides usage instructions, affected products, and references. The code is operational and demonstrates real exploitation, not just detection.
This repository contains a Go-based exploit for CVE-2018-0296, an information disclosure vulnerability in Cisco ASA devices' web interface. The main file, CVE-2018-0296.go, implements the exploit logic: it checks if a given URL points to a Cisco ASA device, determines if it is vulnerable, and, if so, attempts to enumerate valid usernames by sending crafted HTTP requests to specific endpoints. The tool supports optional use of a SOCKS proxy and can operate in a loop mode. The README provides usage instructions and example outputs. The exploit is operational, providing real username enumeration if the target is vulnerable. No hardcoded endpoints are present; the user supplies the target URL. The main fingerprintable endpoints are the Cisco ASA web interface paths used in the exploit. The repository is focused and contains only the exploit code, a README, and build configuration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A directory traversal vulnerability enabling unauthorized access on Cisco ASA and firewall products, referenced as exploited by the actor.
A directory traversal vulnerability in Cisco ASA/firewall products referenced as exploited by the Sea Turtle actors.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.