AI
AI

Decade-Old Cisco Flaw Actively Under Exploitation

Photo credit: www.darkreading.com

Cisco Alerts Customers to Ongoing Security Threat for ASA

Cisco has issued a warning regarding a significant security vulnerability within its Adaptive Security Appliance (ASA), which is reportedly being actively exploited by malicious actors.

The vulnerability, identified as CVE-2014-2120, has existed for nearly a decade. It stems from inadequate input validation on the WebVPN login page of ASA, allowing an unauthenticated attacker to perform a cross-site scripting (XSS) attack.

In its findings from 2014, Cisco stated that this vulnerability arises from “insufficient input validation of a parameter,” noting that the risk comes from convincing users to click on harmful links.

Recently, Cisco reported that it became aware of attempts to exploit this vulnerability in the wild as of November 2024. The company has urged its clients to upgrade to the latest software version to protect against this security flaw, as no effective workarounds are available.

The ongoing exploitation of such long-standing vulnerabilities highlights a significant issue in the realm of cybersecurity. Meny Har, the CEO and co-founder of Opus Security, emphasized in a statement to Dark Reading that “legacy vulnerabilities often linger without resolution due to the overwhelming number of security concerns organizations grapple with today.” He added that without robust prioritization strategies, critical vulnerabilities may go unnoticed, posing a continuous threat to security.

Source
www.darkreading.com

Related by category

Cybersecurity Leaders Condemn ‘Political Persecution’ of Chris Krebs in Letter to the President

Photo credit: www.csoonline.com In November 2018, President Trump appointed Chris...

Broadcom-Supported SAN Devices Vulnerable to Code Injection Attacks Due to Critical Fabric OS Flaw

Photo credit: www.csoonline.com Critical Vulnerability Found in Broadcom’s Brocade Fabric...

Cyberattack on berlin.de | CSO Online

Photo credit: www.csoonline.com Cyberangriff auf Berlins Info- und Serviceportal berlin.de Ende...

Latest news

‘Fateful’ Letter from Doomed Titanic Voyage Sells for Significant Sum at Auction

Photo credit: www.foxnews.com A letter deemed "prophetic," written aboard the...

Explained: Google Search’s Fabricated AI Interpretations of Phrases That Were Never Said

Photo credit: arstechnica.com Understanding Google's AI Interpretations of Nonsense Challenging the...

Exploring Mars: Volcanic History and Evidence of Ancient Life

Photo credit: www.sciencedaily.com A recent study involving a researcher from...

Breaking news