External risk intelligence

Cisco ASA and FTD Directory Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2020-3187

The vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices specifically when configured with WebVPN or AnyConnect features. These features are designed to provide remote access and are typically exposed on the public internet as gateways to internal networks, making them public-facing by design in common deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Cisco devices that provide remote access services. It could allow an unauthorized attacker to access and delete certain files on the device. While the deletion is temporary, the ability to access and manipulate files is a significant concern for security. The main concern is confirming relevance and exposure for your deployed Cisco devices.

  • Attackers can read and delete files via web interfaces.
  • Affects remote access points; data access is the risk.
  • Assess device configurations for potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this by sending a specially crafted HTTP request. This request exploits a flaw in how the device handles URLs, allowing the attacker to traverse directories and access or delete files within the web services file system. This is only possible if the device is configured with WebVPN or AnyConnect features, and it does not grant access to system or operating system files. After exploitation, reloading the device restores any deleted files within this specific file system.

  • Vulnerability triggered by crafted HTTP request.
  • Requires WebVPN or AnyConnect features enabled.
  • Attacker can read or delete web files.

Live Threat

Current exploitation, exposure, and threat context

When Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software are configured with WebVPN or AnyConnect features, an unauthenticated, remote attacker could conduct directory traversal attacks. This could allow the attacker to view or delete arbitrary files within the web services file system on the targeted system.

  • Files in the web services file system at risk.
  • Crafted HTTP request allows file access.
  • Sensitive information may be exposed or deleted.

Operational Fix

Recommended remediation, mitigation, and detection steps

The security teams managing Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices are primarily responsible for addressing this vulnerability, especially if WebVPN or AnyConnect features are enabled. The initial practical step is to identify all instances of the affected technology, determine their exposure and criticality, and then coordinate with Cisco for remediation.

  • Cisco ASA/FTD administrators own the issue.
  • Verify external reachability of affected devices.
  • Plan coordinated vendor remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cisco ASA and FTD software?

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) are security technologies used to protect networks. These products often serve as gateways that manage incoming and outgoing traffic. They are widely used to provide remote access capabilities, such as VPN services, allowing users to securely connect to private corporate networks from remote locations.

What is the weakness class for CVE-2020-3187?

This vulnerability is classified as a Directory Traversal issue (CWE-22). In plain English, it means the software fails to properly check the input in a web address, or URL. Because of this, an attacker can manipulate that address to look at or remove files located in folders they should not be able to reach within the web services file system.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted HTTP request to the device. However, this only works if the device has the WebVPN or AnyConnect features turned on, as these create the specific file system path that is vulnerable. If these features are disabled, the vulnerability cannot be triggered. Importantly, the flaw does not grant access to core operating system files or other sensitive system areas.

Do I need to worry about this?

You should prioritize this if you manage Cisco ASA or FTD devices. According to Halo Surface Signal, these products are often intentionally placed on the public internet to act as remote access gateways, which makes them highly accessible to attackers. If your device is reachable from the internet and has WebVPN or AnyConnect enabled, it is in a position where it could be reached by this threat.

What are the first steps for my team?

First, conduct an inventory to identify all Cisco ASA and FTD devices in your environment. Check their current software versions against the list of affected configurations and verify if WebVPN or AnyConnect features are enabled. Once you have identified vulnerable systems, consult the official Cisco security advisory to plan your update or configuration changes.

References