Cisco Adaptive Security Appliance DOM Cross-Site Scripting Vulnerability in WebVPN Portal

Related Vulnerabilities: CVE-2014-8012  

Cisco Adaptive Security Appliance (ASA) devices configured for WebVPN contain a DOM-based cross-site scripting vulnerability (XSS) within the Portal Login page. An unauthenticated, remote attacker who can convince a user to take a malicious action, could perform a XSS attack on the user. The vulnerability exists due to mishandling of certain attributes that are processed within cookies passed as part of a request. A successful exploit may allow the attacker to execute arbitrary script or HTML code on the user's browser within the context of the affected site. Proof-of-concept code that exploits this vulnerability is publicly available. Cisco has confirmed the vulnerability and released updated software. To exploit the vulnerability, the attacker may provide a link to the user and may persuade the user to follow the link by using misleading language and instructions.