SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-5460

Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText…

MEDIUM 4.3EPSS 0.93%

Does this matter?

Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
0.93% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
juniper/ive os · juniper/secure access virtual appliance · juniper/fips secure access 4000 · juniper/fips secure access 4500 · juniper/fips secure access 6000 · juniper/fips secure access 6500 · juniper/mag2600 gateway · juniper/mag4610 gateway · juniper/mag6610 gateway · juniper/mag6611 gateway · juniper/secure access 2000 · juniper/secure access 2500 · juniper/secure access 4000 · juniper/secure access 4500 · juniper/secure access 6000 · juniper/secure access 6500 · juniper/secure access 700
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.