CVE-2014-2120 - Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Project:Cisco
Product:Adaptive Security Appliance (ASA)
Date Added:2024-11-12Due Date:2024-12-03
Vulnerability Name
Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Description
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CVE-2014-2120
https://nvd.nist.gov/vuln/detail/CVE-2014-2120
Related News Articles
Cisco Warns of Exploitation of Decade-Old ASA WebVPN VulnerabilityDecember 3, 2024