First published: Tue Mar 18 2014(Updated: )
A vulnerability in the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of WebVPN on the Cisco ASA.The vulnerability is due to insufficient input validation of a parameter. An attacker could exploit this vulnerability by convincing a user to access a malicious link.
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2120 has a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2014-2120, update your Cisco Adaptive Security Appliance Software to a version that addresses this vulnerability.
Organizations using Cisco Adaptive Security Appliance Software are vulnerable to CVE-2014-2120.
CVE-2014-2120 allows an unauthenticated remote attacker to carry out a cross-site scripting (XSS) attack.
No, CVE-2014-2120 can be exploited without user authentication, making it particularly concerning.