4.3

CVE-2015-3004

J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D10, 12.3X48 before 12.3X48-D10, 12.2 before 12.2R9, 12.3 before 12.3R7, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R5, 14.1 before 14.1R3, 14.1X53 before 14.1X53-D10, and 14.2 before 14.2R1 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Version12.1x44
JuniperJunos Version12.1x44 Updated10
JuniperJunos Version12.1x44 Updated15
JuniperJunos Version12.1x44 Updated20
JuniperJunos Version12.1x44 Updated25
JuniperJunos Version12.1x44 Updated30
JuniperJunos Version12.1x46
JuniperJunos Version12.1x46 Updated10
JuniperJunos Version12.1x46 Updated15
JuniperJunos Version12.1x46 Updated20
JuniperJunos Version12.1x47
JuniperJunos Version12.2
JuniperJunos Version12.2 Updater1
JuniperJunos Version12.2 Updater2
JuniperJunos Version12.2 Updater3
JuniperJunos Version12.2 Updater4
JuniperJunos Version12.2 Updater5
JuniperJunos Version12.2 Updater6
JuniperJunos Version12.2 Updater7
JuniperJunos Version12.2 Updater8
JuniperJunos Version12.2 Updater8-s2
JuniperJunos Version12.3 Updater1
JuniperJunos Version12.3 Updater2
JuniperJunos Version12.3 Updater3
JuniperJunos Version12.3 Updater4
JuniperJunos Version12.3 Updater5
JuniperJunos Version12.3 Updater6
JuniperJunos Version12.3x48
JuniperJunos Version13.2
JuniperJunos Version13.2 Updater1
JuniperJunos Version13.2 Updater2
JuniperJunos Version13.2 Updater3
JuniperJunos Version13.2 Updater4
JuniperJunos Version13.2 Updater5
JuniperJunos Version13.2x51
JuniperJunos Version13.2x51 Updated10
JuniperJunos Version13.2x51 Updated15
JuniperJunos Version13.3
JuniperJunos Version13.3 Updater1
JuniperJunos Version13.3 Updater2
JuniperJunos Version13.3 Updater2-s2
JuniperJunos Version13.3 Updater3
JuniperJunos Version13.3 Updater4
JuniperJunos Version14.1
JuniperJunos Version14.1 Updater1
JuniperJunos Version14.1 Updater2
JuniperJunos Version14.1x53
JuniperJunos Version14.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.484
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.