18.2 C
Jaipur
Thursday, October 29, 2020

Hackers Exploited CVE-2020-3452 Flaw in Cisco ASA & FTD

Must read

Consumer tech app Streetbees raises $40 million from investors – Latest News

Streetbees, a startup that monitors the emotions of consumers and analyses their purchasing decisions, said on Wednesday it had raised $40 million from investors...

IT: Digitalisation to drive $6.8 trillion IT spending from 2020 to 2023: Report – Latest News

The global economy remains on its way to its "digital destiny" driving USD 6.8 trillion of IT spending from 2020 to 2023, according to...

Set up CUPS Print Server in Ubuntu 20.04 – Linux Hint

The job of a print server is to accept print requests from multiple machines, process those requests, and then send them to...

Javascript Print Page – Linux Hint

Javascript is a scripting or programming language, which is most commonly used nowadays in the web industry. It provides a lot of...

Cisco fixed a high-severity path traversal vulnerability CVE-2020-3452 with Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.

The vulnerability allows a remote attacker to launch a directory traversal attack that allows attackers to read sensitive files on a targeted system.

The vulnerability is due to proper lack of input validation of URLs in HTTP requests, an attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences.

Successful exploitation of the vulnerability allows an attacker to view arbitrary files within the web services file system on the targeted device.

Cisco has released software updates to cover the vulnerability, users with affected products recommended to upgrade to a fixed release as soon as possible.

The flaw reported to Cisco by Mikhail Klyuchnikov of Positive Technologies and Abdulrahman Nour and Ahmed Aboul-Ela from RedForce.

Security researcher Aboul-Ela published a PoC exploit at the time July 22, 14:56 ET and Cognosec researchers published an NMAP script to exploit the flaw.

Hours after the publication of PoC, at 23:31 ET attackers started exploiting the flaw. According to Rapid7’s Project Sonar discovered just over 85,000 ASA/FTD devices, 398 of which are spread across 17% of the Fortune 500.

Rapid7 Labs observed that “only about 10% of Cisco ASA/FTD devices have been rebooted since the release of the patch. This is a likely indicator they’ve been patched (only 27 of the 398 detected in Fortune 500 companies appear to have been patched/rebooted).”

Project Heisenberg(Rapid7 honeypot) observed an IPv4 46[.]30.189.6 address looking for Cisco ASAs internet-wide across 560 ports on 2020-07-18(scan before vulnerability disclosed).

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

Critical Cisco Security Flaws Allow Complete Router Firewall Takeover

Cisco Webex Meetings for Windows Let Hackers Gain Access to Sensitive Data

Source link

- Advertisement -

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article

Consumer tech app Streetbees raises $40 million from investors – Latest News

Streetbees, a startup that monitors the emotions of consumers and analyses their purchasing decisions, said on Wednesday it had raised $40 million from investors...

IT: Digitalisation to drive $6.8 trillion IT spending from 2020 to 2023: Report – Latest News

The global economy remains on its way to its "digital destiny" driving USD 6.8 trillion of IT spending from 2020 to 2023, according to...

Set up CUPS Print Server in Ubuntu 20.04 – Linux Hint

The job of a print server is to accept print requests from multiple machines, process those requests, and then send them to...

Javascript Print Page – Linux Hint

Javascript is a scripting or programming language, which is most commonly used nowadays in the web industry. It provides a lot of...

Javascript Alert – Linux Hint

Javascript is the most known language of the web. Javascript is widely used in front-end development as well as in the back-end. Javascript provides...