Vulnerability Name: | CVE-2014-2151 (CCN-93842) | ||||||||
Assigned: | 2014-06-16 | ||||||||
Published: | 2014-06-16 | ||||||||
Updated: | 2022-06-02 | ||||||||
Summary: | The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-2151 Source: CCN Type: Cisco Security Notice Cisco ASA WebVPN Information Disclosure Vulnerability Source: CISCO Type: Broken Link, Vendor Advisory 20140616 Cisco ASA WebVPN Information Disclosure Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=34627 Source: BID Type: Third Party Advisory, VDB Entry 68063 Source: CCN Type: BID-68063 Cisco Adaptive Security Appliance WebVPN Portal Information Disclosure Vulnerability Source: SECTRACK Type: Broken Link, Third Party Advisory, VDB Entry 1030445 Source: XF Type: UNKNOWN ciscoasa-cve20142151-info-disc(93842) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |