PT-2014-4511 · Cisco · Webvpn+1
Published
2014-06-17
·
Updated
2022-06-02
·
CVE-2014-2151
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance (ASA) Software version 8.4(.7.15) and earlier
Description
A issue in the WebVPN portal allows remote authenticated users to obtain sensitive information via a crafted JavaScript file. This could enable an authenticated, remote attacker to view sensitive information from the affected system.
Recommendations
For Cisco Adaptive Security Appliance (ASA) Software version 8.4(.7.15) and earlier, consider disabling access to the WebVPN portal until a fix is available. Restrict access to sensitive information to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa
Webvpn