CVE-2014-2120

MEDIUM KEV

Cisco ASA - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

Scores

CVSS v3 6.1
EPSS 0.6387
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CISA KEV 2024-11-12
VulnCheck KEV 2024-11-07
InTheWild.io 2024-11-12
ENISA EUVD EUVD-2014-2160
CWE
CWE-79
Status published
Products (2)
cisco/adaptive_security_appliance_software
n/a/n/a
Published Mar 19, 2014
KEV Added Nov 12, 2024
Tracked Since Feb 18, 2026