← Back

CVE-2014-3820

nvd nist
Published: Sep 29, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 before 8.0r1 and the Juniper Junos Pulse Access Control Service devices with UAC OS 4.1 before 4.1r8, 4.4 before 4.4r3 and 5.0 before 5.0r1 allows remote administrators to inject arbitrary web script or HTML via unspecified vectors.

Affected (32)

2 products
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 4.1
Version 4.1r1.1
Version 4.1r1
Version 4.1r2
Version 4.1r3
Version 4.1r4
Version 4.1r5
Version 4.4
Version 4.4 r1
Version 4.4 r2
Version 5.0
Juniper
Version 7.1
Version 7.1r1.1
Version 7.1r10
Version 7.1r11
Version 7.1r12
Version 7.1r13
Version 7.1r14
Version 7.1r15
Version 7.1r1
Version 7.1r2
Version 7.1r3
Version 7.1r4
Version 7.1r5
Version 7.1r6
Version 7.1r7
Version 7.1r8
Version 7.1r9
Version 7.4
Version 7.4 r1.0
Version 7.4 r2.0
Version 8.0

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.