Cisco warns a decade-old vulnerability is back and targeting users




  • A cross-scripting bug plaguing Cisco’s Adaptive Security Appliance is being actively exploited, the company warns
  • The flaw was first discovered a decade ago
  • CISA added it to KEV, and warned federal agencies to patch

Cisco has updated a decade-old advisory to warn users that the ancient vulnerability is now being actively exploited in the wild to spread malware.

Spotted by The Hacker News, the advisory is for a cross-site scripting (XSS) vulnerability affecting the WebVPN login page for the Cisco Adaptive Security Appliance (ASA) Software.

https://cdn.mos.cms.futurecdn.net/UNBhCvCBZ47GpjzV7AN5mG-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img