CVE-2020-3452 What is Cisco ASA and FTD Vulnerability and How to Fix it

Поделиться
HTML-код
  • Опубликовано: 8 сен 2024
  • CVE-2020-3452 is a Cisco ASA and FTD WebVPN Vulnerability with CVSS rating 7.5
    This video is explaining completely about Vulnerability CVE-2020-3452 in Cisco Adaptive Security Appliance ASA and Firepower Threat Defence FTD software which an Unauthenticated attacker could conduct directory traversal attacks by sending a specially crafted HTTP request.
    Successful exploitation would allow the attacker to view sensitive information contained within files on the web services file system (RamFS), which stores data in RAM. As a result, an attacker could gain read-only privileges for WebVPN files, which include the WebVPN configuration of Cisco ASA users, bookmarks, cookies, web content, and HTTP URLs addresses.
    The scariest part of this vulnerability could allow an attacker to impersonate another VPN user and establish a Clientless SSL VPN or AnyConnect VPN session to the device as that user.
    This video is also explaining completely how to fix this vulnerability.

Комментарии • 2

  • @karideeznutz7273
    @karideeznutz7273 3 года назад +1

    i love your videos

  • @Chris-ct2qf
    @Chris-ct2qf 5 месяцев назад

    Why don't you run the command while explaining? It will make more sense instead of just explaining the theory..:(with love)