Directory traversal in Cisco ASA & Cisco Firepower

Published on 10 Jan 2022
Vulnerability

Description

An unauthenticated, remote attacker might use a vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to conduct directory traversal attacks and read sensitive data on a targeted machine. A lack of sufficient input validation of URLs in HTTP requests performed by an affected device is the source of the vulnerability. An attacker could take advantage of this flaw by sending a specially crafted HTTP request to a device that contains directory traversal character sequences. A successful exploit could allow the attacker to view arbitrary files on the affected device’s web services file system. When the afflicted device is setup with WebVPN or AnyConnect functionality, the web services file system is enabled. This vulnerability cannot be used to get access to ASA or FTD system files or the underlying operating system (OS).

Recommendations

  • Update to the latest version
Jijith Rajan
Written by
Cyber Security Engineer

His passion for staying abreast of the latest security threats and trends, coupled with his hands-on experience, allows him to actively contribute to the protection of digital assets. Jijith's dedication and enthusiasm make him a promising talent in the ever-evolving realm of cybersecurity, promising a safer digital future.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo