{"id":19100,"date":"2020-07-25T07:21:25","date_gmt":"2020-07-25T07:21:25","guid":{"rendered":"http:\/\/hraicp.org\/?p=19100"},"modified":"2020-07-25T07:21:25","modified_gmt":"2020-07-25T07:21:25","slug":"%d9%87%d8%b4%d8%af%d8%a7%d8%b1-%d8%a2%d8%b3%db%8c%d8%a8-%d9%be%d8%b0%db%8c%d8%b1%db%8c-%d8%af%d8%b1-cisco-asa-ftd-%d8%a8%d8%a7-%d8%b4%d9%86%d8%a7%d8%b3%d9%87-cve-2020-3452","status":"publish","type":"post","link":"https:\/\/hraicp.org\/?p=19100","title":{"rendered":"\u0647\u0634\u062f\u0627\u0631 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u062f\u0631 Cisco ASA\/FTD \u0628\u0627 \u0634\u0646\u0627\u0633\u0647 CVE-2020-3452"},"content":{"rendered":"<p style=\"text-align: justify\">\u06a9\u0645\u06cc\u062a\u0647 \u0631\u06a9\u0646 \u0686\u0647\u0627\u0631\u0645 &#8211; \u062f\u0631 \u062a\u0627\u0631\u06cc\u062e \u06f2\u06f2 July\u060c \u0633\u06cc\u0633\u06a9\u0648 \u0628\u0647 \u0637\u0648\u0631 \u0631\u0633\u0645\u06cc \u06cc\u06a9 \u0628\u06cc\u0627\u0646\u06cc\u0647 \u0645\u0628\u0646\u06cc \u0628\u0631 \u0648\u062c\u0648\u062f \u06cc\u06a9 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0627\u0632 \u0646\u0648\u0639 Path Traversal \u0631\u0627 \u0645\u0646\u062a\u0634\u0631 \u06a9\u0631\u062f. \u0627\u06cc\u0646 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u06a9\u0647 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 directory traversal \u0646\u06cc\u0632 \u0634\u0646\u0627\u062e\u062a\u0647 \u0645\u06cc \u0634\u0648\u062f \u0628\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc \u062f\u0647\u062f \u062a\u0627 \u0628\u0647 \u0641\u0627\u06cc\u0644 \u0647\u0627 \u0648 \u062f\u0627\u06cc\u0631\u06a9\u062a\u0648\u0631\u06cc \u0647\u0627\u06cc\u06cc \u06a9\u0647 \u062f\u0631 \u0641\u0648\u0644\u062f\u0631 root \u0648\u0628 \u0630\u062e\u06cc\u0631\u0647 \u0634\u062f\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u0646\u062f. \u0628\u0647\u0631\u0647 \u0628\u0631\u062f\u0627\u0631\u06cc \u0647\u06a9\u0631\u0647\u0627 \u0627\u0632 \u0627\u06cc\u0646 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u0645\u0646\u062c\u0631 \u0628\u0647 \u062d\u0645\u0644\u0627\u062a\u06cc \u0627\u0632 \u0642\u0628\u06cc\u0644 \u201cdot-dot-slash\u201d, \u201cdirectory traversal\u201d, \u201cdirectory climbing\u201d \u0648 \u06cc\u0627 \u201cbacktracking\u201d \u0634\u0648\u062f.<\/p>\n<p style=\"text-align: justify\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-19101 aligncenter\" src=\"https:\/\/hraicp.org\/wp-content\/uploads\/2020\/07\/624435-750x460-1.jpg\" alt=\"\" width=\"644\" height=\"395\" srcset=\"https:\/\/hraicp.org\/wp-content\/uploads\/2020\/07\/624435-750x460-1.jpg 750w, https:\/\/hraicp.org\/wp-content\/uploads\/2020\/07\/624435-750x460-1-300x184.jpg 300w\" sizes=\"(max-width: 644px) 100vw, 644px\" \/><\/p>\n<p style=\"text-align: justify\">\u0646\u0642\u0635 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0646\u0631\u0645 \u0627\u0641\u0632\u0627\u0631\u0647\u0627\u06cc\u00a0Cisco Adaptive Security Appliance (ASA) \u0648\u00a0Cisco Firepower Threat Defense (FTD) \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0634\u062f\u0647 \u06a9\u0647 \u0628\u0627 \u0634\u0646\u0627\u0633\u0647\u00a0CVE-2020-3452 \u0642\u0627\u0628\u0644 \u0631\u062f\u06cc\u0627\u0628\u06cc \u0627\u0633\u062a.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"wp-image-4426 aligncenter\" src=\"https:\/\/irancyber.news\/wp-content\/uploads\/2020\/07\/hight-1024x257.png\" alt=\"\u0627\u062e\u0628\u0627\u0631 \u0633\u0627\u06cc\u0628\u0631\u06cc\" width=\"586\" height=\"147\" \/><\/p>\n<p style=\"text-align: justify\"><strong>\u0645\u062e\u062a\u0635\u0631 \u062a\u0648\u0636\u06cc\u062d\u0627\u062a\u06cc \u062f\u0631 \u0645\u0648\u0631\u062f \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0634\u062f\u0647:<\/strong><\/p>\n<p style=\"text-align: justify\">\u0627\u06cc\u0646 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u062f\u0631 \u0631\u0627\u0628\u0637 \u0633\u0631\u0648\u06cc\u0633 \u0648\u0628 \u0646\u0631\u0645 \u0627\u0641\u0632\u0627\u0631 Cisco Adaptive Security Appliance (ASA) \u0648 \u0646\u0631\u0645 \u0627\u0641\u0632\u0627\u0631 Cisco Firepower Default Defence (FTD) \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f \u06a9\u0647 \u0628\u0647 \u06cc\u06a9 \u0645\u0647\u0627\u062c\u0645 \u0627\u0632 \u0631\u0627\u0647 \u062f\u0648\u0631 \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc \u062f\u0647\u062f \u062a\u0627 \u06cc\u06a9 \u062f\u0631\u062e\u0648\u0627\u0633\u062a HTTP \u062f\u0633\u062a\u06a9\u0627\u0631\u06cc \u0634\u062f\u0647 \u0631\u0627 \u0628\u0647 \u062f\u0633\u062a\u06af\u0627\u0647 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631 \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u062f. \u0628\u0627 \u0628\u0647\u0631\u0647 \u0628\u0631\u062f\u0627\u0631\u06cc \u0645\u0648\u0641\u0642\u06cc\u062a \u0622\u0645\u06cc\u0632 \u0627\u0632 \u0646\u0642\u0635 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0645\u0648\u062c\u0648\u062f\u060c \u0645\u0647\u0627\u062c\u0645 \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u062d\u0645\u0644\u0627\u062a \u062a\u062d\u062a \u062f\u0627\u06cc\u0631\u06a9\u062a\u0648\u0631\u06cc \u062e\u0648\u062f \u0631\u0627 \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0641\u0627\u06cc\u0644 \u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0631\u0627 \u0631\u0648\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0647\u062f\u0641 \u0628\u062e\u0648\u0627\u0646\u062f.<\/p>\n<p style=\"text-align: justify\">\u201c\u0641\u0627\u06cc\u0644 \u0633\u06cc\u0633\u062a\u0645 \u0648\u0628 \u0633\u0631\u0648\u06cc\u0633 \u0647\u0646\u06af\u0627\u0645\u06cc \u0641\u0639\u0627\u0644 \u0645\u06cc \u0634\u0648\u062f \u06a9\u0647 \u062f\u0633\u062a\u06af\u0627\u0647 \u0622\u0633\u06cc\u0628 \u062f\u06cc\u062f\u0647 \u0628\u0627 \u0647\u0631 \u062f\u0648 \u0648\u06cc\u0698\u06af\u06cc WebVPN \u06cc\u0627 AnyConnect \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0634\u062f\u0647 \u0628\u0627\u0634\u062f. \u0647\u06a9\u0631\u0647\u0627 \u0646\u0645\u06cc \u062a\u0648\u0627\u0646\u0646\u062f \u0627\u0632 \u0627\u06cc\u0646 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u06cc\u0627\u0628\u06cc \u0628\u0647 \u0641\u0627\u06cc\u0644 \u0647\u0627\u06cc \u0633\u06cc\u0633\u062a\u0645 ASA \u06cc\u0627 FTD \u06cc\u0627 \u0641\u0627\u06cc\u0644 \u0647\u0627\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0639\u0627\u0645\u0644 \u0627\u0635\u0644\u06cc (OS) \u0628\u0647\u0631\u0647 \u0628\u0631\u062f\u0627\u0631\u06cc \u06a9\u0646\u0646\u062f. \u201d<\/p>\n<p style=\"text-align: justify\"><strong>\u0648\u0631\u0698\u0646 \u0647\u0627\u06cc \u062a\u062d\u062a \u062a\u0627\u062b\u06cc\u0631 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc:<\/strong><\/p>\n<ul style=\"text-align: justify\">\n<li>Cisco ASA\uff1a&lt;= 9.6<\/li>\n<li>Cisco ASA\uff1a\u06f9\u066b\u06f7, \u06f9\u066b\u06f8, \u06f9\u066b\u06f9, \u06f9\u066b\u06f1\u06f0, \u06f9\u066b\u06f1\u06f2, \u06f9\u066b\u06f1\u06f3, \u06f9\u066b\u06f1\u06f4<\/li>\n<li>Cisco FTD\uff1a\u06f6\u066b\u06f2\u066b\u06f2 , \u06f6\u066b\u06f2\u066b\u06f3 , \u06f6\u066b\u06f3\u066b\u06f0 , \u06f6\u066b\u06f4\u066b\u06f0 , \u06f6\u066b\u06f5\u066b\u06f0 , \u06f6\u066b\u06f6\u066b\u06f0<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631 \u0628\u0647 \u0634\u0631\u062d \u0632\u06cc\u0631 \u0627\u0633\u062a:<\/strong><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong>\u06f1\u066b Cisco ASA\uff1a<\/strong><\/p>\n<ul style=\"text-align: justify\">\n<li>Cisco ASA Feature =&gt;\u00a0AnyConnect IKEv2 Remote Access (with client services)<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: justify\">Vulnerable Configuration =&gt;\u00a0crypto ikev2 enable &lt;interface_name&gt; client-services port &lt;port #&gt;<\/p>\n<ul style=\"text-align: justify\">\n<li>Cisco ASA Feature =&gt;\u00a0AnyConnect SSL VPN<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: justify\">Vulnerable Configuration =&gt;\u00a0webvpn\u00a0 \u00a0enable &lt;interface_name&gt;<\/p>\n<ul style=\"text-align: justify\">\n<li>Cisco ASA Feature =&gt;\u00a0Clientless SSL VPN<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: justify\">Vulnerable Configuration =&gt;webvpn\u00a0 \u00a0enable &lt;interface_name&gt;<strong><br \/>\n<\/strong><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong>\u06f2\u066b Cisco FTD\uff1a<\/strong><\/p>\n<ul style=\"text-align: justify\">\n<li>Cisco FTD Feature =&gt;\u00a0AnyConnect IKEv2 Remote Access (with client services)1,2<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: justify\">Vulnerable Configuration =&gt;\u00a0crypto ikev2 enable &lt;interface_name&gt; client-services port &lt;port #&gt;<\/p>\n<ul style=\"text-align: justify\">\n<li>Cisco FTD Feature =&gt;\u00a0AnyConnect SSL VPN1,2<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: justify\">Vulnerable Configuration =&gt;\u00a0webvpn\u00a0 \u00a0enable &lt;interface_name&gt;<\/p>\n<p style=\"text-align: justify\"><strong>\u0631\u0627\u0647 \u062d\u0644<\/strong><\/p>\n<p style=\"text-align: justify\">\u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0627\u0647\u06a9\u0627\u0631\u00a0\u0628\u0631\u0627\u06cc \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062d\u0645\u0644\u0627\u062a \u0647\u06a9\u0631\u0647\u0627 \u0646\u0635\u0628 \u0628\u0647 \u0645\u0648\u0642\u0639 \u0648\u0635\u0644\u0647 \u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc\u00a0\u0645\u0631\u0628\u0648\u0637 \u0628\u0647 Cisco ASA \/ TFD \u0645\u06cc \u0628\u0627\u0634\u062f.<\/p>\n<p>\u0645\u0646\u0628\u0639: \u0627\u06cc\u0631\u0627\u0646 \u0633\u0627\u06cc\u0628\u0631<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u06a9\u0645\u06cc\u062a\u0647 \u0631\u06a9\u0646 \u0686\u0647\u0627\u0631\u0645 &#8211; \u062f\u0631 \u062a\u0627\u0631\u06cc\u062e \u06f2\u06f2 July\u060c \u0633\u06cc\u0633\u06a9\u0648 \u0628\u0647 \u0637\u0648\u0631 \u0631\u0633\u0645\u06cc \u06cc\u06a9 \u0628\u06cc\u0627\u0646\u06cc\u0647 \u0645\u0628\u0646\u06cc \u0628\u0631 \u0648\u062c\u0648\u062f \u06cc\u06a9 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u0627\u0632 \u0646\u0648\u0639 Path Traversal \u0631\u0627 \u0645\u0646\u062a\u0634\u0631 \u06a9\u0631\u062f. \u0627\u06cc\u0646 \u0622\u0633\u06cc\u0628 \u067e\u0630\u06cc\u0631\u06cc \u06a9\u0647 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 directory traversal \u0646\u06cc\u0632 \u0634\u0646\u0627\u062e\u062a\u0647 \u0645\u06cc \u0634\u0648\u062f \u0628\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc \u062f\u0647\u062f \u062a\u0627 \u0628\u0647 \u0641\u0627\u06cc\u0644 \u0647\u0627 \u0648 \u062f\u0627\u06cc\u0631\u06a9\u062a\u0648\u0631\u06cc \u0647\u0627\u06cc\u06cc \u06a9\u0647 \u062f\u0631 [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":19101,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,13],"tags":[783,124,467,380],"class_list":["post-19100","post","type-post","status-publish","format-standard","has-post-thumbnail","category-s3-000","category-13","tag-cisco","tag-124","tag-467","tag-380"],"_links":{"self":[{"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/posts\/19100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/hraicp.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19100"}],"version-history":[{"count":1,"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/posts\/19100\/revisions"}],"predecessor-version":[{"id":19102,"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/posts\/19100\/revisions\/19102"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hraicp.org\/index.php?rest_route=\/wp\/v2\/media\/19101"}],"wp:attachment":[{"href":"https:\/\/hraicp.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hraicp.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hraicp.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}