peter bassill · operator
$ cve CVE-2014-2120 JSON

CVE-2014-2120 KEV

6.1
MEDIUM · CVSS 3.1 · EPSS 18.8% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2024-12-03.

Description

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS18.77% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-79
On CISA KEVyes — remediate by 2024-12-03
Public exploitnone known
Published2014-03-19
Last modified2026-06-17

CISA KEV

NameCisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Added2024-11-12
Due2024-12-03
Vendor / productCisco / Adaptive Security Appliance (ASA)
Ransomware usenone reported

Affected (1)

VendorProduct
ciscoadaptive security appliance software

References

→ the Explorer  ·  watch your stack  ·  NVD