Cisco ASA WebVPN Interface Input Validation Vulnerability
Last Update Date:
20 Jun 2014
Release Date:
19 Jun 2014
3708
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in Cisco ASA. A remote user can obtain potentially sensitive information from the target system.
A remote user can create a specially crafted Javascript file that, when loaded by the target authenticated user, will obtain potentially sensitive information from the target system.
Impact
- Information Disclosure
System / Technologies affected
- Cisco ASA
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix.
Vulnerability Identifier
Source
Related Link
Share with