Product Affected

SmartPass WLAN Security Management
Medium
4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Problem

SmartPass WLAN security management application is vulnerable to a cross site scripting (XSS) vulnerability. This can allow remote attackers to obtain sensitive information from users of SmartPass and possibly get access to SmartPass.

CVE: CVE-2013-3498

Solution

This vulnerability is fixed in:
SmartPass 8.0 MR2 or later
SmartPass 7.7 MR3 or later


Workaround

There are no known workarounds that can mitigate XSS issue listed in this bulletin.

Modification History

Modification History:

2017-03-05: Category restructure.

Related Information

Acknowledgements

Juniper Networks Acknowledges with thanks Ross Bushby of KRYPSYS for reporting the issue.