CVE-2014-2120 is a cross-site scripting (XSS) vulnerability affecting the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software, allowing remote attackers to inject arbitrary web script or HTML. Rated Medium with a CVSS score of 6.1, this vulnerability has a low attack complexity and requires user interaction, potentially leading to limited impact on confidentiality and integrity. This flaw is actively exploited in the wild, as indicated by its presence in the KEV catalog and high EPSS score, despite a lack of public exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered significant community discussion and media coverage, highlighting its real-world impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.