CVE-2014-2120: Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Other sources
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2120?
CVE-2014-2120 has been classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2014-2120?
To fix CVE-2014-2120, update the Cisco Adaptive Security Appliance software to the latest version that addresses this vulnerability.
What systems are affected by CVE-2014-2120?
CVE-2014-2120 affects Cisco Adaptive Security Appliance (ASA) software.
Can CVE-2014-2120 be exploited remotely?
Yes, CVE-2014-2120 can be exploited remotely by attackers through the WebVPN login page.
What type of vulnerability is CVE-2014-2120?
CVE-2014-2120 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.