4.3
CVSSv2

CVE-2014-8021

Published: 03/02/2015 Updated: 08/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and previous versions and Cisco HostScan Engine 3.1(.05183) and previous versions allows remote malicious users to inject arbitrary web script or HTML via vectors involving an applet-path URL, aka Bug IDs CSCup82990 and CSCuq80149.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco hostscan engine

cisco anyconnect secure mobility client

Vendor Advisories

A vulnerability in Cisco AnyConnect Secure Mobility Client and Cisco Host Scan could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the client when AnyConnect is launched through the web interface The vulnerability is due to insufficient validation of a URL used to build a path for an ...