Skip to main content

Cisco ASA WebVPN Interface Input Validation Vulnerability

Last Update Date: 20 Jun 2014 Release Date: 19 Jun 2014 3136 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Cisco ASA. A remote user can obtain potentially sensitive information from the target system.

 

A remote user can create a specially crafted Javascript file that, when loaded by the target authenticated user, will obtain potentially sensitive information from the target system.


Impact

  • Information Disclosure

System / Technologies affected

  • Cisco ASA

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link