S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-3452 Scanner

CVE-2020-3452 scanner - Path Traversal vulnerability in Cisco Adaptive Security Appliance (ASA) Software

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-3452
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cisco Adaptive Security Appliance (ASA) Softwareby Cisco
AFFECTED< 9.6.4.42SAFE ✓≥ 9.6.4.42
Updated Aug 21, 2026View on NVD →
Detail

Cisco Adaptive Security Appliance (ASA) Software is a security solution used to protect networks from various threats. This software is designed to provide secure remote access to corporate networks for employees, contractors, and partners. ASA Software provides advanced firewall features, intrusion prevention, VPN services, and other advanced security features. By using this software, businesses can ensure that their data is secure, and that their network is protected from malicious actors.

CVE-2020-3452 is a vulnerability detected in the Cisco Adaptive Security Appliance (ASA) Software that allows an attacker to conduct directory traversal attacks. This vulnerability exists due to the lack of input validation of URLs in HTTP requests processed by an affected device. An attacker can exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to the affected device. A successful exploitation of this vulnerability would allow an attacker to view arbitrary files stored within the web services file system on the targeted device.

When CVE-2020-3452 is exploited, the attacker can gain access to sensitive files, including web server files, which may contain confidential information. The vulnerability can also be used to obtain access to the WebVPN or AnyConnect features configured on the device. This could result in a compromise of sensitive data or unauthorized access to the network.

s4e.io provides advanced features to protect against vulnerabilities in digital assets. This platform provides information about the latest security threats and vulnerabilities affecting various software and hardware products. It also offers tools and services that help businesses protect their networks from malicious actors. By using this platform, users can stay informed about the latest threats and protect their digital assets. With s4e.io, businesses can take proactive measures to secure their network and data and keep their businesses running smoothly.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to take the following precautions:

  • Apply the latest security updates to the affected devices as soon as they become available.
  • Monitor network traffic and look for any suspicious activity.
  • Block access to the affected services from external networks.
  • Maintain a robust and up-to-date antivirus solution.
  • Limit user access to sensitive files and information.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.