PT-2014-4511 · Cisco · Webvpn+1
Publicado
2014-06-17
·
Atualizado
2022-06-02
·
CVE-2014-2151
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance (ASA) Software version 8.4(.7.15) and earlier
Description
A issue in the WebVPN portal allows remote authenticated users to obtain sensitive information via a crafted JavaScript file. This could enable an authenticated, remote attacker to view sensitive information from the affected system.
Recommendations
For Cisco Adaptive Security Appliance (ASA) Software version 8.4(.7.15) and earlier, consider disabling access to the WebVPN portal until a fix is available. Restrict access to sensitive information to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Asa
Webvpn