CVE-2014-2120
KEVlargeCross-Site Scripting in Cisco ASA WebVPN Login Page
CISA: Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
CVE-2014-2120 is a cross-site scripting (CWE-79) vulnerability in the WebVPN login page of the Cisco Adaptive Security Appliance (ASA). A remote, unauthenticated attacker can inject arbitrary web script or HTML through an unspecified parameter of that login page, which is then rendered by a victim's browser. Successful exploitation lets the attacker execute script in the user's browser context, enabling actions such as credential capture, session manipulation, or phishing within the trusted WebVPN page. Only organizations running Cisco ASA devices with the WebVPN (clientless SSL VPN) login page exposed are affected. Despite the flaw's 2014 disclosure, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-12, indicating active exploitation, with no public proof-of-concept code identified.
What to do: Inventory ASA devices and determine whether the WebVPN/clientless SSL VPN login page is enabled and reachable by untrusted users. Upgrade to the fixed releases specified in Cisco's advisory, per the CISA KEV required action, or disable WebVPN if it is not needed. Where mitigations are unavailable, CISA directs organizations to discontinue use of the affected product, so prioritize this for internet-facing VPN endpoints.
| Cisco Adaptive Security Appliance (ASA) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
- Affected
- Cisco Adaptive Security Appliance (ASA)
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Cisco
- Products
- Adaptive Security Appliance (ASA)
- Weakness
- CWE-79