CyberSecurity news

FlagThis

Ameer Owda@socradar.io //
Cisco has confirmed the active exploitation of a decade-old vulnerability, CVE-2014-2120, affecting the WebVPN login page of its Adaptive Security Appliance (ASA) software. This cross-site scripting (XSS) vulnerability, originally disclosed in 2014, allows unauthenticated, remote attackers to launch XSS attacks against WebVPN users by enticing them to click a malicious link. The vulnerability stems from insufficient input validation, enabling attackers to inject malicious scripts into the victim's browser. Cisco's Product Security Incident Response Team (PSIRT) became aware of renewed exploitation attempts in November 2024, prompting an updated advisory urging customers to upgrade to a fixed software release immediately.

While Cisco strongly recommends upgrading to patched software versions, it's important to note that free updates will not be provided for vulnerabilities disclosed through Security Notices. Customers are advised to contact their usual support channels to obtain the necessary upgrades. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2014-2120 to its Known Exploited Vulnerabilities (KEV) catalog in November 2024, further highlighting the critical need for swift remediation. Organizations utilizing third-party support should consult their service providers to ensure compatibility with any applied fixes.
Original img attribution: https://socradar.io/wp-content/uploads/2024/12/old-cisco-asa-vulnerability-cve-2014-2120-fuels-androxgh0st-botnet-activity.jpg.webp
ImgSrc: socradar.io

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • securityonline.info: Cisco Systems has issued an updated security advisory regarding CVE-2014-2120, a vulnerability affecting the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software.
  • The Hacker News: Cisco updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA).
  • malware.news: Cisco warns of continued exploitation of 10-year-old ASA bug, flaw in WebVPN login page exploited in the wild.
  • securityaffairs.com: The ASA flaw CVE-2014-2120 is being actively exploited in the wild
  • www.scworld.com: Cisco warns of continued exploitation of 10-year-old ASA bug
  • Security Risk Advisors: Cisco ASA WebVPN Login Page Vulnerable to Cross-Site Scripting Attack
  • sec.cloudapps.cisco.com: Cisco's security advisory details the vulnerability, its potential impact, and recommendations for mitigation.
  • socradar.io: SOCRadar analysis of the Androxgh0st botnet and its use of the CVE-2014-2120 vulnerability.
  • malware.news: Malware news article discussing the Androxgh0st botnet's utilization of the old Cisco ASA vulnerability.
Classification:
  • HashTags: #Cisco #XSS #WebVPN
  • Company: Cisco
  • Target: Cisco ASA WebVPN users
  • Product: ASA Software
  • Feature: WebVPN login page
  • Malware: CVE-2014-2120
  • Type: Vulnerability
  • Severity: Medium