vendor:
Adaptive Security Appliance
by:
Yassine Aboukir
7.5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Adaptive Security Appliance
Affected Version From: 3000 Series Industrial Security Appliance (ISA)
Affected Version To: Firepower 9300 ASA Security Module
Patch Exists: YES
Related CWE: CVE-2018-0296
CPE: cisco:asa_software
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/cisco_directory_traversal, https://www.infosecmatter.com/nessus-plugin-library/?id=157889, https://www.infosecmatter.com/nessus-plugin-library/?id=157280, https://www.infosecmatter.com/nessus-plugin-library/?id=157894, https://www.infosecmatter.com/nessus-plugin-library/?id=29744, https://www.infosecmatter.com/nessus-plugin-library/?id=20842, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=22954, https://www.infosecmatter.com/nessus-plugin-library/?id=22987, https://www.infosecmatter.com/nessus-plugin-library/?id=86546
Platforms Tested: Windows, Linux, Mac
2018
Cisco Adaptive Security Appliance – Path Traversal (CVE-2018-0296)
A security vulnerability in Cisco ASA that would allow an attacker to view sensitive system information without authentication by using directory traversal techniques.
Mitigation:
Cisco has released software updates that address this vulnerability. Customers may only install and expect support for software versions and feature sets for which they have purchased a license.