CVE-2015-3005: XSS
Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3005?
CVE-2015-3005 is classified as a moderate severity cross-site scripting (XSS) vulnerability that affects certain versions of Juniper Junos.
How do I fix CVE-2015-3005?
To fix CVE-2015-3005, update to the patched versions of Junos, specifically 12.1X44-D45, 12.1X46-D30, 12.1X47-D20, or 12.3X48-D10.
What are the affected versions for CVE-2015-3005?
CVE-2015-3005 affects Juniper Junos versions prior to 12.1X44-D45, 12.1X46-D30, 12.1X47-D20, and 12.3X48-D10.
Can CVE-2015-3005 be exploited remotely?
Yes, CVE-2015-3005 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What is the impact of CVE-2015-3005 if exploited?
If exploited, CVE-2015-3005 can lead to unauthorized actions on behalf of users and potential compromise of sensitive data.