cbcvebase.
CVE-2014-3393
published 2014-10-10

CVE-2014-3393: The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before…

PriorityP276medium4.3CVSS 2.0
AVNACMAuNCNIPAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.99%
78.5th percentile
The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.

Affected

103 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://103.42.181.84/2/css.js
ip103.42.181.84
ip43.251.116.175
domaincscoelab.com
urlhttp://webxss.cn/mu5AOh?1440094244
domainwebxss.cn
pathlogon.html
  • Inspect the source of the Cisco Web VPN logon.html page for unexpected or injected JavaScript/HTML tags, particularly external script includes pointing to non-Cisco domains or IPs.
  • Hunt for Scanbox framework JavaScript URLs injected into Cisco Web VPN portal pages; Scanbox URLs have been associated with Chinese APT activity and are used for browser/software profiling and keystroke capture.
  • A Metasploit module exists for CVE-2014-3393 exploitation; monitor for exploitation attempts targeting the RAMFS customization objects on Cisco ASA devices running affected software versions (8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.4)).
  • ·Exploitation requires knowledge of the targeted device's specific configuration; not all exposed ASA devices are equally trivial to exploit.
  • ·The attack surface also includes administrative access paths (ASDM); restricting ASDM access via ACLs and ensuring it is not Internet-facing reduces the risk of portal tampering even on patched devices.

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vulncheck4.3MEDIUM
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.