🔙 목록으로 돌아가기

CVE-2020-3187: Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal

TitleCisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
AuthorKareemSe1im
SeverityCritical
ImpactAn attacker can exploit this vulnerability to read arbitrary files on the affected system, potentially leading to unauthorized access or sensitive information disclosure.
RemediationApply the necessary security patches or updates provided by Cisco to mitigate the vulnerability.
CVSS Score9.1
EPSS Score0.94341
CVE IDCVE-2020-3187
CWE IDCWE-22
Tags cve cve2020 cisco packetstorm vkev vuln

🔍 Vulnerability Description

Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software are susceptible to directory traversal vulnerabilities that could allow an unauthenticated, remote attacker to obtain read and delete access to sensitive files on a targeted system.

🌐 HTTP Request

GET /+CSCOE+/session_password.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-3187.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-3187.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A