Product Affected
All Juniper DX platforms running DXOS versions older than 5.3.0.
Severity
Medium
Severity Assessment (CVSS) Score
Problem
All Juniper DX platforms running DXOS/Redline revisions older than 5.0.41 and 5.1 versions older than 5.1.7 are vulnerable to a Cross-site Scripting (XSS) Vulnerability as described in CVE-2006-3567 (see link below). The following DXOS/Redline versions are vulnerable.
All versions of 5.0 prior to 5.0.41.
All versions of 5.1 prior to 5.1.7.
All versions prior to 5.0.
This is a old issue resolved in 2006. This PSN is provided for documentation and completion of the CVE information (see CVE-2006-3567 link below).
Solution
DXOS versions 5.0.41, 5.1.7, 5.2.0, 5.3.0, and newer have been modified to protect against this vulnerability.
Juniper DX customers running a vulnerable version of DXOS/Redline are recommended to upgrade to 5.3.0 or newer to become protected against XSS attacks.
Should you have difficulty downloading or installing the appropriate software version, please contact Juniper Support.
Severity Assessment
Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks DX running DXOS versions older than 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the username login field.
Modification History
Modification History:
2017-03-05: Category restructure.
Related Information
DXOS Download Page
NIST Vulnerability Summary - External Link
Contact Juniper Support
Cross-site Scripting (XSS) Vulnerability in DXOS Software