Executive brief
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. Remote attackers can inject arbitrary web script or HTML via an unspecified parameter, potentially leading to session hijacking or unauthorized actions in the context of the user's browser.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software
Timeline
- 2014-03-18: disclosed: Initial NVD publication date
- 2024-11-12: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog