← Back

CVE-2015-3005

nvd nist
Published: Apr 10, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected (16)

Products: Juniper: Junos
1 product
Junos
Configuration A
16 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 12.1x44
Version 12.1x44 d10
Version 12.1x44 d15
Version 12.1x44 d20
Version 12.1x44 d25
Version 12.1x44 d30
Version 12.1x44 d35
Version 12.1x44 d40
Version 12.1x46
Version 12.1x46 d10
Version 12.1x46 d15
Version 12.1x46 d20
Version 12.1x46 d25
Version 12.1x47
Version 12.1x47 d10
Version 12.1x48
Running on/withPlatform Versions
Juniper
Srx100
All versions
Juniper
Srx110
All versions
Juniper
Srx1400
All versions
Juniper
Srx210
All versions
Juniper
Srx220
All versions
Juniper
Srx240
All versions
Juniper
Srx3400
All versions
Juniper
Srx3600
All versions
Juniper
Srx550
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions
Juniper
Srx650
All versions

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.