CVE-2014-2120
Medium CVSS 6.1 Known exploitedPublished 2014-03-19 · last changed 2026-06-17 · added to CISA KEV 2024-11-12
The fix
We hold no Microsoft remediation data for CVE-2014-2120, which normally means it is not a Windows CVE. For non-Microsoft software the fix is the vendor's own updated release, and the affected versions are listed below.
What it is
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
Sources
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N