CVE-2013-3414: XSS
Cross-site scripting (XSS) vulnerability in the WebVPN portal login page on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCug83080.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3414?
CVE-2013-3414 is classified as a medium severity vulnerability due to its impact on user security and potential for exploitation.
How do I fix CVE-2013-3414?
To fix CVE-2013-3414, upgrade to a fixed version of the Cisco Adaptive Security Appliance Software as recommended in Cisco's security advisories.
What systems are affected by CVE-2013-3414?
CVE-2013-3414 affects Cisco Adaptive Security Appliances running various versions of the software that handle WebVPN portal logins.
What type of attack is facilitated by CVE-2013-3414?
CVE-2013-3414 enables attackers to perform cross-site scripting (XSS) attacks through crafted URLs directed at the WebVPN portal login page.
Is user data at risk due to CVE-2013-3414?
Yes, if exploited, CVE-2013-3414 can lead to unauthorized access and manipulation of user data through injected scripts.