ID

VAR-201504-0553


CVE

CVE-2015-3005


TITLE

Juniper SRX Runs on series devices Juniper Junos of Dynamic VPN Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-002206

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Juniper Junos is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Juniper Networks Junos on SRX Series devices is a set of network operating systems of Juniper Networks (Juniper Networks) running on SRX series service gateway devices. The operating system provides a secure programming interface and Junos SDK. The following versions are affected: Juniper Junos 12.1X44 prior to 12.1X44-D45, 12.1X46 prior to 12.1X46-D30, 12.1X47 prior to 12.1X47-D20, and 12.3X48 prior to 12.3X48-D10

Trust: 1.98

sources: NVD: CVE-2015-3005 // JVNDB: JVNDB-2015-002206 // BID: 74016 // VULHUB: VHN-80966

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:12.1x46

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x44

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x47

Trust: 1.6

vendor:junipermodel:junosscope:eqversion:12.1x48

Trust: 1.6

vendor:junipermodel:junos osscope:ltversion:12.1x44

Trust: 0.8

vendor:junipermodel:srx3400scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x47-d20

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.3x48

Trust: 0.8

vendor:junipermodel:srx210scope: - version: -

Trust: 0.8

vendor:junipermodel:srx650scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x46-d30

Trust: 0.8

vendor:junipermodel:srx550scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.1x44-d45

Trust: 0.8

vendor:junipermodel:srx5800scope: - version: -

Trust: 0.8

vendor:junipermodel:srx100scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x46

Trust: 0.8

vendor:junipermodel:srx220scope: - version: -

Trust: 0.8

vendor:junipermodel:srx5600scope: - version: -

Trust: 0.8

vendor:junipermodel:srx110scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:ltversion:12.1x47

Trust: 0.8

vendor:junipermodel:srx240scope: - version: -

Trust: 0.8

vendor:junipermodel:srx1400scope: - version: -

Trust: 0.8

vendor:junipermodel:junos osscope:eqversion:12.3x48-d10

Trust: 0.8

vendor:junipermodel:srx3600scope: - version: -

Trust: 0.8

vendor:junipermodel:junos 12.1x44-d20scope: - version: -

Trust: 0.6

vendor:junipermodel:junos os 12.1x46-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos os 12.1x46-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d11scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos d10scope:eqversion:12.1x47

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d20.5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos d25scope:eqversion:12.1x46

Trust: 0.3

vendor:junipermodel:junos d20scope:eqversion:12.1x46

Trust: 0.3

vendor:junipermodel:junos d15scope:eqversion:12.1x46

Trust: 0.3

vendor:junipermodel:junos d10scope:eqversion:12.1x46

Trust: 0.3

vendor:junipermodel:junos -d10scope:eqversion:12.1x46

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d20scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x45-d10scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d40scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d35scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d34scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d32scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d30.4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d30scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d26scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d25scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d20.3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d15scope: - version: -

Trust: 0.3

vendor:junipermodel:junos d40scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos d35scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos d30scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos d25scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos d20scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos d15scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos d10scope:eqversion:12.1x44

Trust: 0.3

vendor:junipermodel:junos 12.3x48-d10scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x47-d20scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x46-d30scope:neversion: -

Trust: 0.3

vendor:junipermodel:junos 12.1x44-d45scope:neversion: -

Trust: 0.3

sources: BID: 74016 // JVNDB: JVNDB-2015-002206 // CNNVD: CNNVD-201504-183 // NVD: CVE-2015-3005

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3005
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-3005
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201504-183
value: MEDIUM

Trust: 0.6

VULHUB: VHN-80966
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-3005
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-80966
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-80966 // JVNDB: JVNDB-2015-002206 // CNNVD: CNNVD-201504-183 // NVD: CVE-2015-3005

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-80966 // JVNDB: JVNDB-2015-002206 // NVD: CVE-2015-3005

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201504-183

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201504-183

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002206

PATCH

title:JSA10677url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10677

Trust: 0.8

sources: JVNDB: JVNDB-2015-002206

EXTERNAL IDS

db:NVDid:CVE-2015-3005

Trust: 2.8

db:JUNIPERid:JSA10677

Trust: 1.7

db:BIDid:74016

Trust: 1.4

db:SECTRACKid:1032089

Trust: 1.1

db:JVNDBid:JVNDB-2015-002206

Trust: 0.8

db:CNNVDid:CNNVD-201504-183

Trust: 0.7

db:JUNIPERid:JSA10640

Trust: 0.3

db:VULHUBid:VHN-80966

Trust: 0.1

sources: VULHUB: VHN-80966 // BID: 74016 // JVNDB: JVNDB-2015-002206 // CNNVD: CNNVD-201504-183 // NVD: CVE-2015-3005

REFERENCES

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10677

Trust: 1.6

url:http://www.securityfocus.com/bid/74016

Trust: 1.1

url:http://www.securitytracker.com/id/1032089

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3005

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3005

Trust: 0.8

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10640

Trust: 0.3

url:http://www.juniper.net/

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10677

Trust: 0.1

sources: VULHUB: VHN-80966 // BID: 74016 // JVNDB: JVNDB-2015-002206 // CNNVD: CNNVD-201504-183 // NVD: CVE-2015-3005

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 74016

SOURCES

db:VULHUBid:VHN-80966
db:BIDid:74016
db:JVNDBid:JVNDB-2015-002206
db:CNNVDid:CNNVD-201504-183
db:NVDid:CVE-2015-3005

LAST UPDATE DATE

2024-11-23T21:55:18.840000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-80966date:2016-12-03T00:00:00
db:BIDid:74016date:2015-04-09T00:00:00
db:JVNDBid:JVNDB-2015-002206date:2015-04-15T00:00:00
db:CNNVDid:CNNVD-201504-183date:2015-04-14T00:00:00
db:NVDid:CVE-2015-3005date:2024-11-21T02:28:29.587

SOURCES RELEASE DATE

db:VULHUBid:VHN-80966date:2015-04-10T00:00:00
db:BIDid:74016date:2015-04-09T00:00:00
db:JVNDBid:JVNDB-2015-002206date:2015-04-15T00:00:00
db:CNNVDid:CNNVD-201504-183date:2015-04-14T00:00:00
db:NVDid:CVE-2015-3005date:2015-04-10T15:00:09.477