← Back

CVE-2017-2335

nvd nist
Published: Jul 17, 2017Modified: May 13, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue.

Affected (24)

Products: Juniper: Screenos
1 product
Screenos
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 6.3.0
Version 6.3.0 r10
Version 6.3.0 r11
Version 6.3.0 r12
Version 6.3.0 r13
Version 6.3.0 r14
Version 6.3.0 r15
Version 6.3.0 r16
Version 6.3.0 r17
Version 6.3.0 r18
Version 6.3.0 r19
Version 6.3.0 r1
Version 6.3.0 r21
Version 6.3.0 r22
Version 6.3.0 r23
Version 6.3.0 r23b
Version 6.3.0 r2
Version 6.3.0 r3
Version 6.3.0 r4
Version 6.3.0 r5
Version 6.3.0 r6
Version 6.3.0 r7
Version 6.3.0 r8
Version 6.3.0 r9

References (6)

Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
Third Party AdvisoryVDB Entry
Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.