CVE-2012-1038
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3…
Does this matter?
Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- juniper/networks mobility system software
- Source
- cve@mitre.org
References
- http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=viewVendor Advisory
- http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdfBroken Link
- http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/Third Party Advisory
- http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2012-06-611&viewMode=viewVendor Advisory
- http://www.secureworks.com/advisories/swrx-2012-004/SWRX-2012-004.pdfBroken Link
- http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-004/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.