>> All posts

CVE-2020-3452: Cisco ASA/FTD web-services path traversal, unauthenticated file read

The short version: Cisco ASA and Firepower Threat Defense (FTD) software have a directory-traversal flaw in their web services (CVE-2020-3452) that lets an unauthenticated attacker read files from the appliance's web-services filesystem. It's read-only — no code execution, no writes to system files — but it's trivially exploitable, has public exploits, is heavily scanned, and sits in CISA's KEV catalog. Patch and confirm exposure. Steady hands.

At a glance

FactDetail
Our severity takeModerate — an unauthenticated, mass-exploited information leak
CVSS v3.1 (NVD)7.5 — High · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS~99.99% · 99.99th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2022-05-03
Known exploited?Yes — public exploits, widespread scanning and exploitation
Vulnerability typeCWE-22 path traversal (CWE-20 improper input validation) → unauthenticated read of files in the web-services subsystem
Requires authenticated session?No — pre-authentication
AffectedASA and FTD software with web services (WebVPN / AnyConnect / clientless SSL VPN) enabled — e.g. ASA 9.6 < 9.6.4.42, 9.8 < 9.8.4.20, 9.12 < 9.12.3.12, 9.14 < 9.14.1.10; FTD 6.2.3 < 6.2.3.16, 6.4.0 < 6.4.0.10, 6.6.0 < 6.6.0.1 (see advisory for the full table)
Fixed inThe fixed maintenance release for each affected train (per Cisco advisory cisco-sa-asaftd-ro-path-KJuQhB86)

What you need to know

ASA and FTD are Cisco's firewall/VPN platforms. When their web services are enabled — the components behind clientless SSL VPN and AnyConnect — a flaw in how the software handles certain requests lets an unauthenticated attacker traverse directories and read files served by that subsystem.

The scope is important, in both directions:

  • It's read-only, and bounded to the web-services filesystem. An attacker can't write files, run code, or (per Cisco) read files from the underlying operating system or reach the appliance's configuration through this bug. That keeps it out of "instant total compromise" territory.
  • But the files it can reach still matter, and it's dead simple to fire at scale. With public exploit code and near-universal scanning, an exposed, affected appliance will be found and probed.

The reason this ranks higher than a typical 7.5 in the wild is exposure and volume: it's an internet-facing security appliance, unauthenticated, and one of the most reliably scanned Cisco bugs of its era.

How serious we see it

Moderate — on paper it's a 7.5, and in the real world it's an unauthenticated, mass-exploited leak on a perimeter device.

We don't inflate it to Critical, because it's genuinely read-only and doesn't hand over code execution or the OS. But KEV listing, public exploits, and an EPSS at the very top of the scale mean an exposed, affected ASA/FTD is being touched — so we treat it as a prompt-fix item, not a someday item. The bounded, reassuring part: it only affects devices with web services enabled, the fixes are long published, and exposure is quick to confirm.

Recommendations

Straight from Cisco's advisory and CISA:

  1. Patch now. Upgrade each affected ASA/FTD train to its fixed maintenance release per cisco-sa-asaftd-ro-path-KJuQhB86.
  2. Reduce exposure. If clientless SSL VPN / web services aren't required, disable them; restrict who can reach the VPN web interface.
  3. Confirm your exposure first. Verify whether you run an affected ASA/FTD build with web services enabled and reachable from the internet.
  4. Hunt. Review web-services and VPN logs for traversal-style requests and unexpected file access.
  5. Rotate what was reachable. Treat anything the web-services subsystem could expose as potentially read, and rotate accordingly.

How BreachRisk sees it

BreachRisk answers the first question — do we have an exposed, affected appliance? — from the outside in. Starting from little more than your domain, it discovers internet-facing Cisco ASA/FTD VPN web interfaces, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one, surfaced at the top of your results because it's in KEV.

That continuous, attacker's-eye view is what makes an old-but-still-scanned bug manageable: the exposed appliance is already mapped, so you go straight to patch-and-confirm.

References

See your cyber risk, proven.