Cisco Warns of Exploitation of Decade-Outdated ASA WebVPN Vulnerability

Dec 03, 2024Ravie LakshmananVulnerability / Community Safety

Cisco on Monday up to date an advisory to warn prospects of lively exploitation of a decade-old safety flaw impacting its Adaptive Safety Equipment (ASA).

The vulnerability, tracked as CVE-2014-2120 (CVSS rating: 4.3), issues a case of inadequate enter validation in ASA’s WebVPN login web page that might enable an unauthenticated, distant attacker to conduct a cross-site scripting (XSS) assault in opposition to a focused person of the equipment.

“An attacker could exploit this vulnerability by convincing a user to access a malicious link,” Cisco famous in an alert launched in March 2014.

As of December 2, 2024, the networking tools main has revised its bulletin to notice that it has turn into conscious of “additional attempted exploitation” of the vulnerability within the wild.

Cybersecurity

The event comes shortly after cybersecurity agency CloudSEK revealed that the risk actors behind AndroxGh0st are leveraging an intensive listing of safety vulnerabilities in varied internet-facing purposes, together with CVE-2014-2120, to propagate the malware.

The malicious exercise can also be notable for the mixing of the Mozi botnet, which permits the botnet to additional broaden in dimension and scope.

Consequently, the U.S. Cybersecurity and Infrastructure Safety Company (CISA) added the flaw to its Identified Exploited Vulnerabilities (KEV) catalog final month, requiring Federal Civilian Government Department (FCEB) companies to remediate it by December 3, 2024.

Customers of Cisco ASA are extremely really helpful to maintain their installations up-to-date for optimum safety and to safeguard in opposition to potential cyber threats.

Discovered this text attention-grabbing? Observe us on Twitter and LinkedIn to learn extra unique content material we put up.

Recent articles

U.S. Sanctions Chinese language Cybersecurity Agency Over Treasury Hack Tied to Silk Hurricane

The U.S. Treasury Division's Workplace of International Property Management...

FTC cracks down on Genshin Impression gacha loot field practices

Genshin Impression developer Cognosphere (aka Hoyoverse)...

New ‘Sneaky 2FA’ Phishing Package Targets Microsoft 365 Accounts with 2FA Code Bypass

Jan 17, 2025Ravie LakshmananCybersecurity / Menace Intelligence Cybersecurity researchers have...