Vulnerability record · CVE-2020-3187 · published 6 May 2020
CVE-2020-3187: Cisco ASA/FTD Web Services Directory Traversal Allows File Read and Delete
Cisco · Secure Firewall Threat Defense
Cisco ASA and FTD web services fail to validate HTTP URLs, allowing directory traversal sequences in crafted requests. An unauthenticated remote attacker can read or delete files inside the web services file system, which is active only when WebVPN or AnyConnect is configured. Deleted files are restored on device reload, and ASA/FTD system and OS files are out of reach.
Description
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with no authentication or user interaction, public exploit code, and an EPSS score above the 99.8th percentile make this a high-urgency remote file read/delete flaw.
What it is
Cisco ASA and FTD web services fail to validate HTTP URLs, allowing directory traversal sequences in crafted requests. An unauthenticated remote attacker can read or delete files inside the web services file system, which is active only when WebVPN or AnyConnect is configured. Deleted files are restored on device reload, and ASA/FTD system and OS files are out of reach.
Impact
The attacker gains read and delete access to files in the web services file system, exposing sensitive content and enabling destructive deletion of those files. No access to ASA/FTD system files or the underlying OS is possible, and reloading the device restores deleted files.
Attack surface
Reachable over the network through the web services interface via a crafted HTTP request containing directory traversal sequences. No authentication or user interaction is required, and the interface must be enabled through WebVPN or AnyConnect configuration.
Exploitation
Public exploit code is referenced (Packet Storm, tagged Exploit), and EPSS is 0.96595 (99.881st percentile), indicating very high predicted exploitation activity. The CVE is not listed in CISA KEV.
What to do
- Apply the Cisco security advisory patch for ASA and FTD software as the first action.
- If WebVPN or AnyConnect web services are not required, disable them to remove the exposed interface.
- Restrict network access to the web services interface to trusted management networks only.
- After patching, reload the device to restore any files deleted during prior exploitation.
- Monitor Cisco advisories for updated fixed releases and verify the running version against them.
Detection
- Inspect HTTP requests to the ASA/FTD web services interface for directory traversal sequences such as ../ or encoded variants.
- Alert on unexpected file deletion or access events within the web services file system.
- Review web services access logs for anomalous unauthenticated requests from external or untrusted sources.
- Correlate device reloads with prior suspicious web services activity to identify restored deleted files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158648/Cisco-Adaptive-Security-Appliance-Software-9.7-Arbitrary-File-Deletion.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-path-JE3azWw43 | Vendor Advisory |
| http://packetstormsecurity.com/files/158648/Cisco-Adaptive-Security-Appliance-Software-9.7-Arbitrary-File-Deletion.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-path-JE3azWw43 | Vendor Advisory |
Track CVE-2020-3187 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3187), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.