Description
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system.
Remediation
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
References
Related Vulnerabilities
Squid Improper Input Validation Vulnerability (CVE-2014-3609)
Joomla Improper Input Validation Vulnerability (CVE-2021-26036)
Ruby Improper Input Validation Vulnerability (CVE-2015-1855)
OpenSSL Improper Input Validation Vulnerability (CVE-2015-1787)
WordPress Plugin Import Export WordPress Users CSV Injection (1.3.1)