First published: Mon Sep 29 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos Pulse Access Control Service | =7.1 | |
Juniper Junos Pulse Access Control Service | =7.1r1 | |
Juniper Junos Pulse Access Control Service | =7.1r1.1 | |
Juniper Junos Pulse Access Control Service | =7.1r2 | |
Juniper Junos Pulse Access Control Service | =7.1r3 | |
Juniper Junos Pulse Access Control Service | =7.1r4 | |
Juniper Junos Pulse Access Control Service | =7.1r5 | |
Juniper Junos Pulse Access Control Service | =7.1r6 | |
Juniper Junos Pulse Access Control Service | =7.1r7 | |
Juniper Junos Pulse Access Control Service | =7.1r8 | |
Juniper Junos Pulse Access Control Service | =7.1r9 | |
Juniper Junos Pulse Access Control Service | =7.1r10 | |
Juniper Junos Pulse Access Control Service | =7.1r11 | |
Juniper Junos Pulse Access Control Service | =7.1r12 | |
Juniper Junos Pulse Access Control Service | =7.1r13 | |
Juniper Junos Pulse Access Control Service | =7.1r14 | |
Juniper Junos Pulse Access Control Service | =7.1r15 | |
Juniper Junos Pulse Access Control Service | =7.4-r1.0 | |
Juniper Junos Pulse Access Control Service | =7.4-r2.0 | |
Juniper Junos Pulse Access Control Service | =7.4-r3.0 | |
Juniper Junos Pulse Access Control Service | =7.4-r4.0 | |
Juniper Junos Pulse Access Control Service | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3824 has been assigned a medium severity rating due to its cross-site scripting (XSS) vulnerability.
To remediate CVE-2014-3824, upgrade your Junos Pulse Secure Access Service to version 8.0r6, 7.4r13, or 7.1r20 or later.
CVE-2014-3824 affects Juniper Junos Pulse Secure Access Service versions prior to 8.0r6, 7.4r13, and 7.1r20.
CVE-2014-3824 allows remote attackers to inject arbitrary web scripts or HTML, which could compromise user information.
CVE-2014-3824 was reported in 2014, highlighting serious security risks that require prompt attention.