The ASA flaw CVE-2014-2120 is being actively exploited in the wild

Share:

Cisco warns customers that a decade-old ASA vulnerability, tracked as CVE-2014-2120, is being actively exploited in the wild.

Cisco warns that the decade-old ASA vulnerability CVE-2014-2120 is being actively exploited in attacks in the wild, and urges customers to review the updated advisory.

The vulnerability resides in the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software, an unauthenticated, remote attacker could exploit the flaw to conduct a cross-site scripting (XSS) attack against a user of WebVPN on the Cisco ASA.

“A vulnerability in the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of WebVPN on the Cisco ASA.” reads the advisory. “The vulnerability is due to insufficient input validation of a parameter. An attacker could exploit this vulnerability by convincing a user to access a malicious link.”

The networking giant first published the advisory on March 18, 2024, however in November 2024, Cisco PSIRT detected new exploitation attempts for the vulnerability.

“In November 2024, the Cisco Product Security Incident Response Team (PSIRT) became aware of additional attempted exploitation of this vulnerability in the wild.” continues the advisory. “Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability.”

In November, the US CISA added the vulnerability CVE-2014-2120 to its Known Exploited Vulnerabilities (KEV) catalog.

SOURCE

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:38 pm, Jan 17, 2025
weather icon 4°C
L: 3° | H: 5°
overcast clouds
Humidity: 86 %
Pressure: 1034 mb
Wind: 3 mph SE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:57 am
Sunset: 4:23 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
3° | 5°°C 0 mm 0% 4 mph 90 % 1034 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
1° | 6°°C 0 mm 0% 6 mph 90 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 92 % 1020 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 5 mph 95 % 1019 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
3° | 8°°C 1 mm 100% 12 mph 98 % 1013 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 4°°C 0 mm 0% 3 mph 86 % 1034 mb 0 mm/h
Tomorrow 3:00 am
weather icon
2° | 3°°C 0 mm 0% 2 mph 87 % 1033 mb 0 mm/h
Tomorrow 6:00 am
weather icon
2° | 3°°C 0 mm 0% 1 mph 90 % 1032 mb 0 mm/h
Tomorrow 9:00 am
weather icon
2° | 2°°C 0 mm 0% 2 mph 87 % 1031 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 67 % 1030 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 61 % 1027 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 81 % 1026 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 3°°C 0 mm 0% 3 mph 88 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,710.06
4.64%
Ethereum(ETH)
€3,389.97
5.62%
XRP(XRP)
€3.19
2.85%
Tether(USDT)
€0.97
0.05%
Solana(SOL)
€214.38
4.72%
Dogecoin(DOGE)
€0.403571
9.91%
USDC(USDC)
€0.97
0.01%
Shiba Inu(SHIB)
€0.000023
10.82%
Pepe(PEPE)
€0.000019
13.25%
Peanut the Squirrel(PNUT)
€0.64
9.47%
Scroll to Top