CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: May 3, 2022
CVE-2020-3452
Description
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
EPSS — Exploit Probability
Higher than 100.0% of all CVEs
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2020-3452
Risk Assessment
HIGHDetails
- Severity
- High
- EPSS
- 94.5%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Nov 3, 2021
Added to KEV
Nov 3, 2021
Remediation Due
May 3, 2022
Affected Product
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
View all Cisco CVEs