5.4

CVE-2017-2336

ScreenOS: XSS vulnerability in ScreenOS Firewall

A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the attacker to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Screenos Version 6.3.0
Juniper ≫ Screenos Version 6.3.0 Update r1
Juniper ≫ Screenos Version 6.3.0 Update r10
Juniper ≫ Screenos Version 6.3.0 Update r11
Juniper ≫ Screenos Version 6.3.0 Update r12
Juniper ≫ Screenos Version 6.3.0 Update r13
Juniper ≫ Screenos Version 6.3.0 Update r14
Juniper ≫ Screenos Version 6.3.0 Update r15
Juniper ≫ Screenos Version 6.3.0 Update r16
Juniper ≫ Screenos Version 6.3.0 Update r17
Juniper ≫ Screenos Version 6.3.0 Update r18
Juniper ≫ Screenos Version 6.3.0 Update r19
Juniper ≫ Screenos Version 6.3.0 Update r2
Juniper ≫ Screenos Version 6.3.0 Update r21
Juniper ≫ Screenos Version 6.3.0 Update r22
Juniper ≫ Screenos Version 6.3.0 Update r23
Juniper ≫ Screenos Version 6.3.0 Update r23b
Juniper ≫ Screenos Version 6.3.0 Update r3
Juniper ≫ Screenos Version 6.3.0 Update r4
Juniper ≫ Screenos Version 6.3.0 Update r5
Juniper ≫ Screenos Version 6.3.0 Update r6
Juniper ≫ Screenos Version 6.3.0 Update r7
Juniper ≫ Screenos Version 6.3.0 Update r8
Juniper ≫ Screenos Version 6.3.0 Update r9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.64
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.3 2.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
Juniper 9.6 2.8 6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://www.securityfocus.com/bid/99590
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038881
Third Party Advisory
VDB Entry
https://kb.juniper.net/JSA10782
Vendor Advisory