← Vulnerability feed

Vulnerability record · CVE-2020-3187 · published 6 May 2020

CVE-2020-3187: Cisco ASA/FTD Web Services Directory Traversal Allows File Read and Delete

Cisco · Secure Firewall Threat Defense

Cisco ASA and FTD web services fail to validate HTTP URLs, allowing directory traversal sequences in crafted requests. An unauthenticated remote attacker can read or delete files inside the web services file system, which is active only when WebVPN or AnyConnect is configured. Deleted files are restored on device reload, and ASA/FTD system and OS files are out of reach.

9.1 CVSS 3.1 Critical EPSS 97% · top 0.1% CWE-22 · Path traversal
9.1CVSS 3.1 base score, v2 7.5
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
14Affected product versions listed by NVD
4References, 2 tagged exploit
11 Aug 2026Last modified by NVD

Description

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.1 with no authentication or user interaction, public exploit code, and an EPSS score above the 99.8th percentile make this a high-urgency remote file read/delete flaw.

What it is

Cisco ASA and FTD web services fail to validate HTTP URLs, allowing directory traversal sequences in crafted requests. An unauthenticated remote attacker can read or delete files inside the web services file system, which is active only when WebVPN or AnyConnect is configured. Deleted files are restored on device reload, and ASA/FTD system and OS files are out of reach.

Impact

The attacker gains read and delete access to files in the web services file system, exposing sensitive content and enabling destructive deletion of those files. No access to ASA/FTD system files or the underlying OS is possible, and reloading the device restores deleted files.

Attack surface

Reachable over the network through the web services interface via a crafted HTTP request containing directory traversal sequences. No authentication or user interaction is required, and the interface must be enabled through WebVPN or AnyConnect configuration.

Exploitation

Public exploit code is referenced (Packet Storm, tagged Exploit), and EPSS is 0.96595 (99.881st percentile), indicating very high predicted exploitation activity. The CVE is not listed in CISA KEV.

What to do

  • Apply the Cisco security advisory patch for ASA and FTD software as the first action.
  • If WebVPN or AnyConnect web services are not required, disable them to remove the exposed interface.
  • Restrict network access to the web services interface to trusted management networks only.
  • After patching, reload the device to restore any files deleted during prior exploitation.
  • Monitor Cisco advisories for updated fixed releases and verify the running version against them.

Detection

  • Inspect HTTP requests to the ASA/FTD web services interface for directory traversal sequences such as ../ or encoded variants.
  • Alert on unexpected file deletion or access events within the web services file system.
  • Review web services access logs for anomalous unauthenticated requests from external or untrusted sources.
  • Correlate device reloads with prior suspicious web services activity to identify restored deleted files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3187 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2020-3452Cisco ASA and FTD web services path traversal file readCisco ASA and FTD web services fail to validate URL input, allowing directory traversal sequences in HTTP requests to read files inside the web servi…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3187), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.