Product Affected

All Juniper DX platforms running DXOS versions older than 5.3.0.
Medium

Problem


All Juniper DX platforms running DXOS/Redline revisions older than 5.0.41 and 5.1 versions older than 5.1.7 are vulnerable to a Cross-site Scripting (XSS) Vulnerability as described in CVE-2006-3567 (see link below). The following DXOS/Redline versions are vulnerable.

  • All versions of 5.0 prior to 5.0.41.
  • All versions of 5.1 prior to 5.1.7.
  • All versions prior to 5.0.

This is a old issue resolved in 2006. This PSN is provided for documentation and completion of the CVE information (see CVE-2006-3567 link below).

Solution


DXOS versions 5.0.41, 5.1.7, 5.2.0, 5.3.0, and newer have been modified to protect against this vulnerability.
Juniper DX customers running a vulnerable version of DXOS/Redline are recommended to upgrade to 5.3.0 or newer to become protected against XSS attacks.

Should you have difficulty downloading or installing the appropriate software version, please contact Juniper Support.

Severity Assessment

Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks DX running DXOS versions older than 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the username login field.

Modification History

Modification History:

2017-03-05: Category restructure.

Related Information