Junglewise Threat Intelligence

CVE-2014-2120: Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

CVE-2014-2120 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2024-11-12

Technologies: Cisco Adaptive Security Appliance (ASA) Software, Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD). Vendors: Cisco.

Executive brief

Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. Remote attackers can inject arbitrary web script or HTML via an unspecified parameter, potentially leading to session hijacking or unauthorized actions in the context of the user's browser.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software

Timeline

  • 2014-03-18: disclosed: Initial NVD publication date
  • 2024-11-12: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog

Related threats