CVE-2020-3452: Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion

HoneyLabs honeypots recorded 46 probes matching CVE-2020-3452 from 14 distinct source IP addresses in the last 7 days. Severity is rated high.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
  • /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=..

Addresses probing it

Source IPProbesNetworkCountry
195.128.248.3331Virtual Systems LLCUkraine
134.209.53.363DigitalOcean, LLCUnited States
159.223.119.461DigitalOcean, LLCUnited States
45.79.192.1451Akamai Connected CloudUnited States
68.183.23.121DigitalOcean, LLCUnited States
165.227.16.1421DigitalOcean, LLCUnited States
45.33.15.501Akamai Connected CloudUnited States
68.183.138.501DigitalOcean, LLCUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS6698Virtual Systems LLC311
AS14061DigitalOcean, LLC108
AS63949Akamai Connected Cloud55

Captured requests

  • /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2BCSCOE%2B/portal_inc.lua
  • /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
  • /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../../
  • /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../

HTTP client fingerprints (JA4H)

  • ge11nn0400_cf1edba2959c
  • ge11nn0300_dedeb29cc523

CVE report

CVE report

Open a specific CVE from the CVE tracker.