4.3
CVE-2014-3824
- EPSS 0.23%
- Veröffentlicht 29.09.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Cross-site scripting (XSS) vulnerability in the web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Pulse Secure Access Service Version7.1
Juniper ≫ Junos Pulse Secure Access Service Version7.1r1
Juniper ≫ Junos Pulse Secure Access Service Version7.1r1.1
Juniper ≫ Junos Pulse Secure Access Service Version7.1r2
Juniper ≫ Junos Pulse Secure Access Service Version7.1r3
Juniper ≫ Junos Pulse Secure Access Service Version7.1r4
Juniper ≫ Junos Pulse Secure Access Service Version7.1r5
Juniper ≫ Junos Pulse Secure Access Service Version7.1r6
Juniper ≫ Junos Pulse Secure Access Service Version7.1r7
Juniper ≫ Junos Pulse Secure Access Service Version7.1r8
Juniper ≫ Junos Pulse Secure Access Service Version7.1r9
Juniper ≫ Junos Pulse Secure Access Service Version7.1r10
Juniper ≫ Junos Pulse Secure Access Service Version7.1r11
Juniper ≫ Junos Pulse Secure Access Service Version7.1r12
Juniper ≫ Junos Pulse Secure Access Service Version7.1r13
Juniper ≫ Junos Pulse Secure Access Service Version7.1r14
Juniper ≫ Junos Pulse Secure Access Service Version7.1r15
Juniper ≫ Junos Pulse Secure Access Service Version7.4 Updater1.0
Juniper ≫ Junos Pulse Secure Access Service Version7.4 Updater2.0
Juniper ≫ Junos Pulse Secure Access Service Version7.4 Updater3.0
Juniper ≫ Junos Pulse Secure Access Service Version7.4 Updater4.0
Juniper ≫ Junos Pulse Secure Access Service Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.423 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.