CVE-2020-3452
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
⚠ KEVEPSS 100.0%
描述
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
如何修補 CVE-2020-3452
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2020-3452 正在被利用嗎?
是 — CVE-2020-3452 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。