Vulnerability record · CVE-2014-2120 · published 19 March 2014
CVE-2014-2120: Cisco ASA WebVPN login page cross-site scripting
Cisco · Adaptive Security Appliance Software
The WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software reflects an unspecified parameter without proper encoding, allowing injection of arbitrary script or HTML. Because the flaw sits on a login page, it is well suited to credential theft or session hijacking against users who reach the portal.
Description
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is a medium-severity XSS but is listed in CISA KEV with known exploitation and a high EPSS percentile, so it warrants prompt remediation.
What it is
The WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software reflects an unspecified parameter without proper encoding, allowing injection of arbitrary script or HTML. Because the flaw sits on a login page, it is well suited to credential theft or session hijacking against users who reach the portal.
Impact
An attacker can run script in the context of the WebVPN portal in a victim's browser, enabling theft of credentials or session data and redirection or content spoofing on the login page.
Attack surface
Reachable over the network through the WebVPN login page; no authentication is required to deliver the payload, but the victim must interact with a crafted link or page (UI:R per the CVSS vector).
Exploitation
CVE-2014-2120 is listed in CISA KEV with a 2024-11-12 addition date, indicating known exploitation; EPSS shows a 30-day probability of 0.189 (97th percentile). No ransomware campaign use is recorded.
What to do
- Apply the vendor fix or mitigation per Cisco's advisory for Bug ID CSCun19025; if no fix is available for the running release, upgrade to a supported ASA version.
- If patching cannot be done promptly, restrict or disable WebVPN login page exposure to untrusted networks and follow CISA's required action to discontinue use where mitigations are unavailable.
- Validate and encode all input rendered on the WebVPN login page, and enforce a strict Content-Security-Policy on the portal.
- Place the WebVPN portal behind a reverse proxy or WAF with XSS filtering and monitor for encoded script payloads in login requests.
Detection
- Inspect ASA/WebVPN HTTP logs and proxy logs for script tags, event handlers or encoded payloads in requests to the WebVPN login page.
- Alert on referrer or redirect chains that send users to the WebVPN login URL with unexpected query parameters.
- Monitor for credential-harvesting pages mimicking the ASA WebVPN login and for anomalous authentication attempts from unusual sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-2120 to the Known Exploited Vulnerabilities catalog on 12 November 2024 as "Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2120 | Broken LinkVendor Advisory |
| http://www.securityfocus.com/bid/66290 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1029935 | Broken LinkThird Party AdvisoryVDB Entry |
| http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2120 | Broken LinkVendor Advisory |
| http://www.securityfocus.com/bid/66290 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1029935 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-2120 | US Government Resource |
Track CVE-2014-2120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.