CVE-2014-2120
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 19, 2014
Updated: Dec 19, 2024
CWE ID 79
Summary
CVE-2014-2120 is a cross-site scripting (XSS) vulnerability affecting the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software. An attacker can exploit this flaw by injecting arbitrary web scripts or HTML code into an unspecified parameter, potentially gaining unauthorized access to users' sessions or stealing sensitive information. This issue, identified as Bug ID CSCun19025, poses a significant risk to organizations using the affected software, making it essential to apply the available patches promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.