← Back

CVE-2014-3393

nvd nist
Published: Oct 10, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.

Affected (102)

1 product
Configuration A
102 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 8.2.0.45
Version 8.2.1.1
Version 8.2.1
Version 8.2.2.10
Version 8.2.2.12
Version 8.2.2.16
Version 8.2.2.17
Version 8.2.2
Version 8.2.3
Version 8.2.4.1
Version 8.2.4.4
Version 8.2.4
Version 8.2.5.13
Version 8.2.5.22
Version 8.2.5.26
Version 8.2.5.33
Version 8.2.5.40
Version 8.2.5.41
Version 8.2.5.46
Version 8.2.5.48
Version 8.2.5.50
Version 8.2.5
Version 8.2
Version 8.3.1.1
Version 8.3.1.4
Version 8.3.1.6
Version 8.3.1
Version 8.3.2.13
Version 8.3.2.23
Version 8.3.2.25
Version 8.3.2.31
Version 8.3.2.33
Version 8.3.2.34
Version 8.3.2.37
Version 8.3.2.39
Version 8.3.2.40
Version 8.3.2.41
Version 8.3.2.4
Version 8.3.2
Version 8.3
Version 8.4.1.11
Version 8.4.1.3
Version 8.4.1
Version 8.4.2.1
Version 8.4.2.8
Version 8.4.2
Version 8.4.3.8
Version 8.4.3.9
Version 8.4.3
Version 8.4.4.1
Version 8.4.4.3
Version 8.4.4.5
Version 8.4.4.9
Version 8.4.4
Version 8.4.5.6
Version 8.4.5
Version 8.4.6
Version 8.4.7.15
Version 8.4.7.22
Version 8.4.7.3
Version 8.4.7
Version 8.4
Version 8.6.1.10
Version 8.6.1.12
Version 8.6.1.13
Version 8.6.1.14
Version 8.6.1.1
Version 8.6.1.2
Version 8.6.1.5
Version 8.6.1
Version 8.6
Version 9.0.1
Version 9.0.2.10
Version 9.0.2
Version 9.0.3.6
Version 9.0.3.8
Version 9.0.3
Version 9.0.4.17
Version 9.0.4.1
Version 9.0.4.20
Version 9.0.4.24
Version 9.0.4.5
Version 9.0.4.7
Version 9.0.4
Version 9.0
Version 9.1.1.4
Version 9.1.1
Version 9.1.2.8
Version 9.1.2
Version 9.1.3.2
Version 9.1.3
Version 9.1.4
Version 9.1.5.10
Version 9.1.5.12
Version 9.1.5.15
Version 9.1.5
Version 9.1
Version 9.2.0
Version 9.2.1
Version 9.2.2.4
Version 9.2.2
Version 9.2.3

Timeline

No history available yet.