Description
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system.
Remediation
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
References
Related Vulnerabilities
MediaWiki Improper Input Validation Vulnerability (CVE-2011-1580)
WordPress Plugin User Photo 'user-photo.php' Arbitrary File Upload (0.9.4)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Directory Traversal (1.3.42)
WordPress 5.5.x Directory Traversal (5.5 - 5.5.14)
WordPress Duplicator plugin Unauthenticated Arbitrary File Download