CyberSec.Space Logo
返回 CVE 浏览器

CVE-2017-2335

HIGH
8.4
CVSS Severity Score
EPSS Score0.0980%
EPSS Percentile17.04th
Published2017年7月17日
Last Modified2026年5月13日

Vulnerability Description

A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue.

Affected Platforms (CPE)

💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0
💻
Juniper

Screenos

= 6.3.0

References & Advisories

相关漏洞威胁