CVE-2014-2120 KEV
6.1
MEDIUM · CVSS 3.1 · EPSS 18.8% (pctl 97)
Patch first
On CISA KEV — known exploited in the wild, due 2024-12-03.
Description
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 18.77% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | yes — remediate by 2024-12-03 |
| Public exploit | none known |
| Published | 2014-03-19 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability |
|---|---|
| Added | 2024-11-12 |
| Due | 2024-12-03 |
| Vendor / product | Cisco / Adaptive Security Appliance (ASA) |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| cisco | adaptive security appliance software |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2120
- http://www.securityfocus.com/bid/66290
- http://www.securitytracker.com/id/1029935
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2120
- http://www.securityfocus.com/bid/66290
- http://www.securitytracker.com/id/1029935
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-2120
→ the Explorer · watch your stack · NVD