
Script proof-of-concept per CVE-2020-3452 — vulnerabilità di Path Traversal in Cisco ASA/FTD. Supporta l'estrazione automatica di target di file noti con un limite massimo di download riusciti per sicurezza. Destinato esclusivamente a test di sicurezza autorizzati e scopi di ricerca.
Script proof-of-concept per CVE-2020-3452 — vulnerabilità Path Traversal su Cisco ASA/FTD. Supporta l'estrazione automatica di file target noti con un limite massimo di download riusciti per sicurezza. Destinato esclusivamente a test di sicurezza autorizzati e scopi di ricerca.
Script proof-of-concept per CVE-2020-3452 — vulnerabilità Path Traversal su Cisco ASA/FTD. Supporta l'estrazione automatica di file target noti con un limite massimo di download riusciti per sicurezza. Destinato esclusivamente a test di sicurezza autorizzati e scopi di ricerca.
# CVE-2020-3452 PoC — Cisco ASA/FTD Path Traversal
This is a modified proof-of-concept exploit script for [CVE-2020-3452](https://nvd.nist.gov/vuln/detail/CVE-2020-3452), a directory traversal vulnerability affecting Cisco ASA and FTD devices.
The vulnerability allows unauthenticated, remote attackers to **read arbitrary files** on affected systems via a crafted HTTP request. This script automates that process by attempting to retrieve a predefined list of common configuration, portal, and HTML files, and stores successful responses locally.
> **⚠️ For authorized testing and research only. Use responsibly.**
---
## ✅ Features
- 🔁 Iterates through a curated list of target file paths known to exist on ASA/FTD systems.
- ✅ Only writes responses with **HTTP 200** and **non-empty content**.
- 🧮 Stops automatically after **200 successful downloads** to prevent abuse or noise.
- 🗂️ Writes all files to an `output/` directory, creating it automatically.
- 🔒 Sanitizes all output filenames to prevent accidental traversal or injection.
- 🧼 Suppresses SSL warnings (ASA certs are often self-signed).
---
## 🖥️ Usage
```bash
# Install dependencies
pip install requests
# Run the script
python3 cve_2020_3452.py <target-host>
```
Example:
```bash
python3 cve_2020_3452.py firewall.example.com
```
All successful files will be saved to the `output/` folder.
You may also run the script interactively:
```bash
python3 cve_2020_3452.py
```
---
## 🔧 Configuration
| Variable | Description |
| -------------------- | --------------------------------------------------------------------- |
| `MAX_SUCCESS_WRITES` | Stops script after this number of HTTP 200 file saves (default: 200). |
| `OUTPUT_DIR` | Directory where files will be written (default: `output/`). |
You can safely edit these at the top of the script.
---
## 📚 Background
* **CVE**: [CVE-2020-3452](https://nvd.nist.gov/vuln/detail/CVE-2020-3452)
* **Affected**:
* Cisco ASA: 9.6 – 9.14.1.10
* Cisco FTD: 6.2.3 – 6.6.0.1
* **Impact**: Allows unauthenticated file disclosure via crafted URL traversal.
---
## ⚠️ Legal & Ethical Notice
This script is provided **for educational and authorized security research purposes only**.
* 🛑 **Do NOT use** this tool on systems you do not own or explicitly have permission to test.
* 🧑⚖️ Unauthorized use may be illegal and unethical under local, federal, or international law.
* 🤝 You assume all responsibility for use of this tool.
---
## 🙏 Credits
* Original author: [@freakyclown](https://github.com/cygenta)
* Modifications: hard-coded success limit, file hygiene, output directory isolation
---
## 📜 License
MIT License — see [`LICENSE`](https://github.com/abrewer251/cve-2020-3452_cisco_asa_pathtraversal/blob/HEAD/LICENSE) for details.
Includilo nel tuo repository per semplificare la configurazione:
requests