Cisco ASA flaw CVE-2014
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-2120 | Cross-Site Scripting in Cisco ASA WebVPN Login Page CVE-2014-2120 is a cross-site scripting (CWE-79) vulnerability in the WebVPN login page of the Cisco Adaptive Security Appliance (ASA). A remote, unauthenticated attacker can inject arbitrary web script or HTML through an unspecified parameter of that login page, which is then rendered by a victim's browser. Successful exploitation lets the attacker execute script in the user's browser context, enabling actions such as credential capture, session manipulation, or phishing within the trusted WebVPN page. Only organizations running Cisco ASA devices with the WebVPN (clientless SSL VPN) login page exposed are affected. Despite the flaw's 2014 disclosure, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-12, indicating active exploitation, with no public proof-of-concept code identified. Do: Inventory ASA devices and determine whether the WebVPN/clientless SSL VPN login page is enabled and reachable by untrusted users. Upgrade to the fixed releases specified in Cisco's advisory, per the CISA KEV required action, or disable WebVPN if it is not needed. Where mitigations are unavailable, CISA directs organizations to discontinue use of the affected product, so prioritize this for internet-facing VPN endpoints. | — | 19% | KEV |
| largeon the order of 100,000+ internet-exposed Cisco ASA/VPN gateways (subset with WebVPN enabled) |
Full article252 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 03, 2024

Cisco warns customers that a decade-old ASA vulnerability, tracked as CVE-2014-2120, is being actively exploited in the wild.
Cisco warns that the decade-old ASA vulnerability CVE-2014-2120 is being actively exploited in attacks in the wild, and urges customers to review the updated advisory.
The vulnerability resides in the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software, an unauthenticated, remote attacker could exploit the flaw to conduct a cross-site scripting (XSS) attack against a user of WebVPN on the Cisco ASA.
“A vulnerability in the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of WebVPN on the Cisco ASA.” reads the advisory. “The vulnerability is due to insufficient input validation of a parameter. An attacker could exploit this vulnerability by convincing a user to access a malicious link.”
The networking giant first published the advisory on March 18, 2024, however in November 2024, Cisco PSIRT detected new exploitation attempts for the vulnerability.
“In November 2024, the Cisco Product Security Incident Response Team (PSIRT) became aware of additional attempted exploitation of this vulnerability in the wild.” continues the advisory. “Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability.”
In November, the US CISA added the vulnerability CVE-2014-2120 to its Known Exploited Vulnerabilities (KEV) catalog.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Cisco)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171631/hacking/cisco-asa-flaw-cve-2014-2120-exploited-in-the-wild.html