[██████████.mil] Cisco VPN Service Path Traversal
Team Summary
Official summary from U.S. Dept Of Defense
The target server was using Cisco VPN Service, which was vulnerable to CVE-2020-3452 allowing an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files within the web services file system.
Vulnerability Details
Technical details and impact analysis
Related CVEs
Associated Common Vulnerabilities and Exposures
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input …
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Path Traversal