CVE-2014-2120: Cisco Adaptive Security Appliance (ASA)
EPSS22.5%No. 1093 of 1739 in KEV
CVE year2014~10 yrs before listing
Same vendor in KEV100
Same product4
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | Adaptive Security Appliance (ASA) |
| Name | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability |
| Added to KEV | 2024-11-12 |
| US federal due date | 2024-12-03 |
| Ransomware use | Unknown |
| CWE | CWE-79 |
CISA description
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2016-6367 | Cisco Adaptive Security Appliance (ASA) | 2022-05-24 | 22.5% | Unknown |
| CVE-2016-6366 | Cisco Adaptive Security Appliance (ASA) | 2022-05-24 | 87.5% | Unknown |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | 2021-11-03 | 99.9% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco Adaptive Security Appliance (ASA) vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12.