Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.
http://www.securitytracker.com/id/1031395
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8012