On Monday, Cisco revised a notification to alert clients about ongoing exploitation of a ten-year-old vulnerability affecting its Adaptive Security Appliance (ASA).
The security loophole, identified as CVE-2014-2120 (CVSS score: 4.3), pertains to a scenario of inadequate input validation in the ASA’s WebVPN login interface, potentially enabling an unauthorized, remote hacker to execute a cross-site scripting (XSS) assault
The security loophole, identified as CVE-2014-2120 (CVSS score: 4.3), pertains to a scenario of inadequate input validation in the ASA’s WebVPN login interface, potentially enabling an unauthorized, remote hacker to execute a cross-site scripting (XSS) assault
