vendor:
Adaptive Security Appliance Software
by:
0xmmnbassel
7.5
CVSS
HIGH
unauthenticated file read
20
CWE
Product Name: Adaptive Security Appliance Software
Affected Version From: Cisco ASA Software >=9.14 except 9.11 Cisco FTD Software >=6.2.2 and 6.2.3,6.3.0,6.4.0,6.50,6.60
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2020-3452
CPE: a:cisco:adaptive_security_appliance_software
Other Scripts:
N/A
Platforms Tested: N/A
2020
Cisco Adaptive Security Appliance Software 9.11 – Local File Inclusion
Cisco ASA Software >=9.14 except 9.11 Cisco FTD Software >=6.2.2 and 6.2.3,6.3.0,6.4.0,6.50,6.60 are vulnerable to unauthenticated file read. An attacker can exploit this vulnerability by sending a crafted request to the targeted system.
Mitigation:
Upgrade to the latest version of Cisco ASA Software and Cisco FTD Software.