← Vulnerability feed

Vulnerability record · CVE-2014-2120 · published 19 March 2014

CVE-2014-2120: Cisco ASA WebVPN login page cross-site scripting

Cisco · Adaptive Security Appliance Software

The WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software reflects an unspecified parameter without proper encoding, allowing injection of arbitrary script or HTML. Because the flaw sits on a login page, it is well suited to credential theft or session hijacking against users who reach the portal.

6.1 CVSS 3.1 Medium CISA KEV since 12 Nov 2024 EPSS 19% · top 2.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
19%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a medium-severity XSS but is listed in CISA KEV with known exploitation and a high EPSS percentile, so it warrants prompt remediation.

What it is

The WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software reflects an unspecified parameter without proper encoding, allowing injection of arbitrary script or HTML. Because the flaw sits on a login page, it is well suited to credential theft or session hijacking against users who reach the portal.

Impact

An attacker can run script in the context of the WebVPN portal in a victim's browser, enabling theft of credentials or session data and redirection or content spoofing on the login page.

Attack surface

Reachable over the network through the WebVPN login page; no authentication is required to deliver the payload, but the victim must interact with a crafted link or page (UI:R per the CVSS vector).

Exploitation

CVE-2014-2120 is listed in CISA KEV with a 2024-11-12 addition date, indicating known exploitation; EPSS shows a 30-day probability of 0.189 (97th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the vendor fix or mitigation per Cisco's advisory for Bug ID CSCun19025; if no fix is available for the running release, upgrade to a supported ASA version.
  • If patching cannot be done promptly, restrict or disable WebVPN login page exposure to untrusted networks and follow CISA's required action to discontinue use where mitigations are unavailable.
  • Validate and encode all input rendered on the WebVPN login page, and enforce a strict Content-Security-Policy on the portal.
  • Place the WebVPN portal behind a reverse proxy or WAF with XSS filtering and monitor for encoded script payloads in login requests.

Detection

  • Inspect ASA/WebVPN HTTP logs and proxy logs for script tags, event handlers or encoded payloads in requests to the WebVPN login page.
  • Alert on referrer or redirect chains that send users to the WebVPN login URL with unexpected query parameters.
  • Monitor for credential-harvesting pages mimicking the ASA WebVPN login and for anomalous authentication attempts from unusual sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-2120 to the Known Exploited Vulnerabilities catalog on 12 November 2024 as "Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2020-3452Cisco ASA and FTD web services path traversal file readCisco ASA and FTD web services fail to validate URL input, allowing directory traversal sequences in HTTP requests to read files inside the web servi…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2014-2120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.