Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects Cisco devices that provide remote access services. It could allow an unauthorized attacker to access and delete certain files on the device. While the deletion is temporary, the ability to access and manipulate files is a significant concern for security. The main concern is confirming relevance and exposure for your deployed Cisco devices.
- Attackers can read and delete files via web interfaces.
- Affects remote access points; data access is the risk.
- Assess device configurations for potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this by sending a specially crafted HTTP request. This request exploits a flaw in how the device handles URLs, allowing the attacker to traverse directories and access or delete files within the web services file system. This is only possible if the device is configured with WebVPN or AnyConnect features, and it does not grant access to system or operating system files. After exploitation, reloading the device restores any deleted files within this specific file system.
- Vulnerability triggered by crafted HTTP request.
- Requires WebVPN or AnyConnect features enabled.
- Attacker can read or delete web files.
Live Threat
Current exploitation, exposure, and threat context
When Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software are configured with WebVPN or AnyConnect features, an unauthenticated, remote attacker could conduct directory traversal attacks. This could allow the attacker to view or delete arbitrary files within the web services file system on the targeted system.
- Files in the web services file system at risk.
- Crafted HTTP request allows file access.
- Sensitive information may be exposed or deleted.
Operational Fix
Recommended remediation, mitigation, and detection steps
The security teams managing Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices are primarily responsible for addressing this vulnerability, especially if WebVPN or AnyConnect features are enabled. The initial practical step is to identify all instances of the affected technology, determine their exposure and criticality, and then coordinate with Cisco for remediation.
- Cisco ASA/FTD administrators own the issue.
- Verify external reachability of affected devices.
- Plan coordinated vendor remediation.