CVE-2014-2120
MEDIUM KEVCisco ASA - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
References (4)
Scores
CVSS v3
6.1
EPSS
0.6387
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CISA KEV
2024-11-12
VulnCheck KEV
2024-11-07
InTheWild.io
2024-11-12
ENISA EUVD
EUVD-2014-2160
CWE
CWE-79
Status
published
Products (2)
cisco/adaptive_security_appliance_software
n/a/n/a
Published
Mar 19, 2014
KEV Added
Nov 12, 2024
Tracked Since
Feb 18, 2026