SmartPass WLAN security management application is vulnerable to a cross site scripting (XSS) vulnerability. This can allow remote attackers to obtain sensitive information from users of SmartPass and possibly get access to SmartPass. CVE: CVE-2013-3498
This vulnerability is fixed in: SmartPass 8.0 MR2 or later SmartPass 7.7 MR3 or later
There are no known workarounds that can mitigate XSS issue listed in this bulletin.
2017-03-05: Category restructure.
Juniper Networks Acknowledges with thanks Ross Bushby of KRYPSYS for reporting the issue.