CVE-2020-3452: Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
HoneyLabs honeypots recorded 46 probes matching CVE-2020-3452 from 14 distinct source IP addresses in the last 7 days. Severity is rated high.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
- /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=..
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 195.128.248.33 | 31 | Virtual Systems LLC | Ukraine |
| 134.209.53.36 | 3 | DigitalOcean, LLC | United States |
| 159.223.119.46 | 1 | DigitalOcean, LLC | United States |
| 45.79.192.145 | 1 | Akamai Connected Cloud | United States |
| 68.183.23.12 | 1 | DigitalOcean, LLC | United States |
| 165.227.16.142 | 1 | DigitalOcean, LLC | United States |
| 45.33.15.50 | 1 | Akamai Connected Cloud | United States |
| 68.183.138.50 | 1 | DigitalOcean, LLC | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS6698 | Virtual Systems LLC | 31 | 1 |
| AS14061 | DigitalOcean, LLC | 10 | 8 |
| AS63949 | Akamai Connected Cloud | 5 | 5 |
Captured requests
- /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2BCSCOE%2B/portal_inc.lua
- /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
- /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../../
- /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
HTTP client fingerprints (JA4H)
- ge11nn0400_cf1edba2959c
- ge11nn0300_dedeb29cc523
CVE report
CVE report
Open a specific CVE from the CVE tracker.