CVE-2020-3452
CISA 기관 조치 기한: 2022-05-03
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Qualys 위협 인텔 · 심각도 4/5 · QID 38792 · General remote services
공개 익스플로잇
실제 공격 관측
쉬운 악용
CISA KEV
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC
- GitHub 공개 PoC 19건 — 대표 레포 ↗
- Exploit-DB: EDB-49262 ↗