Feed/CVE-2020-3452
CVE-2020-3452HIGHCVSS 7.5CISA KEV: Actively Exploited

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Published Nov 3, 2021·Updated Aug 11, 2026

NVD Description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

Public Exploits & PoCs19 found

[POC] CVE-2020-3452 — CISCO-CVE-2020-3452-Scanner-Exploiter

CISCO CVE-2020-3452 Scanner & Exploiter

33

[POC] CVE-2020-3452 — CVE-2020-3452

CVE-2020-3452 exploit

26

[POC] CVE-2020-3452 — CVE-2020-3452-Cisco-Scanner

CVE-2020-3452 Cisco ASA Scanner -unauth Path Traversal Check

26

[POC] CVE-2020-3452 — CVE-2020-3452-Exploit

Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.

9

[POC] CVE-2020-3452 — CVE-2020-3452

[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal

9

[POC] CVE-2020-3452 — CVE-2020-3452

Little, stupid python validator(?) for CVE-2020-3452 on CISCO devices.

3

[POC] CVE-2020-3452 — Cisco-ASA-FTD-Web-Services-Traversal

CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) traversal

2

[POC] CVE-2020-3452 — cve-2020-3452

unauth file read in cisco asa & firepower.

2

[POC] CVE-2020-3452 — Cisco-ASA-LFI

(CVE-2020-3452) Cisco Adaptive Security Appliance Software - Local File Inclusion Vuln Test sciript

1

[POC] CVE-2020-3452 — Cisco-CVE-2020-3452-shodan-scanner

simple bash script of CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability checker

1

PoC: CVE-2020-3452-Cisco-Python-Scanner

Safe Python scanner for CVE-2020-3452 (Cisco ASA/FTD WebVPN Directory Traversal)

PoC: CVE-2020-3452_Cisco_ASA_PathTraversal

Proof-of-concept script for CVE-2020-3452 — Cisco ASA/FTD Path Traversal vulnerability. Supports automated extraction of known file targets with a hard limit on successful downloads for safety. Intended for authorized security testing and research purposes only.

PoC: CVE-2020-3452

Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion

PoC: CVE-2020-3452

Exploitation Scanner CVE-2020-3452 to enumerate the standard files accessible in the Path Traversal of CISCO ASA/FTD .🔥

PoC: cve-2020-3452

Just proof of concept for Cisco CVE-2020-3452. Using external or internal file base.

PoC: CVE-2020-3452

Test vulnerability of CVE-2020-3452

PoC: CVE-2020-3452

CVE-2020-3452

PoC: CVE-2020-3452

CVE-2020-3452 - directory traversal in Cisco ASA and Cisco Firepower Threat Defense

PoC: http-vuln-cve2020-3452.nse

CVE-2020-3452 : Cisco ASA and FTD Unauthorized Remote File Reading Nmap NSE Script

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free