Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-3452_Cisco_ASA_PathTraversal — Proof-of-concept exploit for CVE-2020-3452, a path traversal in Cisco ASA/FTD, enabling unauthenticated file disclosure. Automates extraction of known files with safety limits for authorized testing. | Kitploit
Tools/GitHubGitHub/abrewer251/cve-2020-3452_cisco_asa_pathtraversal
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHubabrewer251/cve-2020-3452_cisco_asa_pathtraversal

CVE-2020-3452_Cisco_ASA_PathTraversal

Proof-of-concept exploit for CVE-2020-3452, a path traversal in Cisco ASA/FTD, enabling unauthenticated file disclosure. Automates extraction of known files with safety limits for authorized testing.

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-3452_Cisco_ASA_PathTraversal

Proof-of-concept script for CVE-2020-3452 — Cisco ASA/FTD Path Traversal vulnerability. Supports automated extraction of known file targets with a hard limit on successful downloads for safety. Intended for authorized security testing and research purposes only.


🔐 GitHub Repository Description

Proof-of-concept script for CVE-2020-3452 — Cisco ASA/FTD Path Traversal vulnerability. Supports automated extraction of known file targets with a hard limit on successful downloads for safety. Intended for authorized security testing and research purposes only.


📄 README.md

# CVE-2020-3452 PoC — Cisco ASA/FTD Path Traversal

This is a modified proof-of-concept exploit script for [CVE-2020-3452](https://nvd.nist.gov/vuln/detail/CVE-2020-3452), a directory traversal vulnerability affecting Cisco ASA and FTD devices.

The vulnerability allows unauthenticated, remote attackers to **read arbitrary files** on affected systems via a crafted HTTP request. This script automates that process by attempting to retrieve a predefined list of common configuration, portal, and HTML files, and stores successful responses locally.

> **⚠️ For authorized testing and research only. Use responsibly.**

---

## ✅ Features

- 🔁 Iterates through a curated list of target file paths known to exist on ASA/FTD systems.
- ✅ Only writes responses with **HTTP 200** and **non-empty content**.
- 🧮 Stops automatically after **200 successful downloads** to prevent abuse or noise.
- 🗂️ Writes all files to an `output/` directory, creating it automatically.
- 🔒 Sanitizes all output filenames to prevent accidental traversal or injection.
- 🧼 Suppresses SSL warnings (ASA certs are often self-signed).

---

## 🖥️ Usage

```bash
# Install dependencies
pip install requests

# Run the script
python3 cve_2020_3452.py <target-host>

Example:

python3 cve_2020_3452.py firewall.example.com

All successful files will be saved to the output/ folder.

You may also run the script interactively:

python3 cve_2020_3452.py

🔧 Configuration

VariableDescription
MAX_SUCCESS_WRITESStops script after this number of HTTP 200 file saves (default: 200).
OUTPUT_DIRDirectory where files will be written (default: output/).

You can safely edit these at the top of the script.


📚 Background

  • CVE: CVE-2020-3452

  • Affected:

    • Cisco ASA: 9.6 – 9.14.1.10
    • Cisco FTD: 6.2.3 – 6.6.0.1
  • Impact: Allows unauthenticated file disclosure via crafted URL traversal.


⚠️ Legal & Ethical Notice

This script is provided for educational and authorized security research purposes only.

  • 🛑 Do NOT use this tool on systems you do not own or explicitly have permission to test.
  • 🧑‍⚖️ Unauthorized use may be illegal and unethical under local, federal, or international law.
  • 🤝 You assume all responsibility for use of this tool.

🙏 Credits

  • Original author: @freakyclown
  • Modifications: hard-coded success limit, file hygiene, output directory isolation

📜 License

MIT License — see LICENSE for details.


---

## 📦 requirements.txt

Include this in your repo to make setup easier:

```txt
requests

📜 LICENSE (MIT)

MIT License

Copyright (c) 2025

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction...


Download Tool