The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2151 | Broken Link Vendor Advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=34627 | Vendor Advisory |
http://www.securityfocus.com/bid/68063 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1030445 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
02 Jun 2022, 15:45
Type | Values Removed | Values Added |
---|---|---|
References | (SECTRACK) http://www.securitytracker.com/id/1030445 - Broken Link, Third Party Advisory, VDB Entry | |
References | (CISCO) http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2151 - Broken Link, Vendor Advisory | |
CPE | cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(1.3\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(4.5\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(7\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(4.9\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(4.3\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(2.1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(5.6\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(6\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(7.3\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(4.1\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(3.9\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(4\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(2.8\):*:*:*:*:*:*:* cpe:2.3:a:cisco:adaptive_security_appliance_software:8.4\(3.8\):*:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo |
Information
Published : 2014-06-18 16:55
Updated : 2023-12-10 11:31
NVD link : CVE-2014-2151
Mitre link : CVE-2014-2151
CVE.ORG link : CVE-2014-2151
JSON object : View
Products Affected
cisco
- adaptive_security_appliance_software
CWE