Cisco says decade-old bug in ASA appliances exploited in the wild

Cisco says decade-old bug in ASA appliances exploited in the wild

Networking giant Cisco has updated its advisory to alert users about active exploitation of a ten-year-old vulnerability in its Adaptive Security Appliance (ASA) product.

The vulnerability, tracked as CVE-2014-2120, stems from insufficient input validation in ASA's WebVPN login page. Exploitation of this flaw could allow a remote, unauthenticated attacker to launch a cross-site scripting (XSS) attack, potentially compromising targeted users of the appliance.

The activity involving CVE-2014-2120 has been linked to the Mozi botnet, enabling attackers to amplify the scale and scope of their malicious campaigns. The Mozi botnet is infamous for its ability to exploit vulnerabilities in IoT and network devices.

Cisco is urging users of its ASA software to update their installations to the latest versions to prevent future attacks.

Back to the list

Latest Posts

US agencies warn of rising cyber threats from Iran-linked hackers

US agencies warn of rising cyber threats from Iran-linked hackers

Recent months have seen a notable uptick in activity from Iranian-linked hacktivists and government-affiliated threat groups.
1 July 2025
Google rolls out urgent Chrome security patch for active zero-day

Google rolls out urgent Chrome security patch for active zero-day

The flaw, tracked as CVE-2025-6554, is described as a type confusion bug in Chrome's V8 JavaScript and WebAssembly engine.
1 July 2025
Canada bans Chinese surveillance firm Hikvision over national security concerns

Canada bans Chinese surveillance firm Hikvision over national security concerns

From now on, all federal departments, agencies, and Crown corporations are prohibited from purchasing Hikvision products.
1 July 2025