CVE-2014-2151
published 2014-06-18CVE-2014-2151: The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information…
PriorityP416medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.40%
69.3th percentile
The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | <= 8.4\(7.15\) | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w9vr-w6m4-g679: The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8
ghsa_unreviewed·2022-05-13
CVE-2014-2151 [MEDIUM] CWE-20 GHSA-w9vr-w6m4-g679: The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8
The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.
Cisco
Cisco Adaptive Security Appliance Software WebVPN Information Disclosure Vulnerability
vendor_cisco·2014-06-17·CVSS 4.0
CVE-2014-2151 [MEDIUM] CWE-200 Cisco Adaptive Security Appliance Software WebVPN Information Disclosure Vulnerability
Cisco Adaptive Security Appliance Software WebVPN Information Disclosure Vulnerability
A vulnerability in the WebVPN portal of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, remote attacker to view sensitive information from the affected system.
The vulnerability is due to improper input validation in the WebVPN portal. An attacker could exploit this vulnerability by providing a crafted JavaScript file to an authenticated WebVPN user.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must authenticate to a targeted device. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, th
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2151http://tools.cisco.com/security/center/viewAlert.x?alertId=34627http://www.securityfocus.com/bid/68063http://www.securitytracker.com/id/1030445http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2151http://tools.cisco.com/security/center/viewAlert.x?alertId=34627http://www.securityfocus.com/bid/68063http://www.securitytracker.com/id/1030445
2014-06-18
Published