Critical severity9.6NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2017-2336
CVE-2017-2336
Description
A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the attacker to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue.
Affected products
25cpe:2.3:o:juniper:screenos:6.3.0:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:o:juniper:screenos:6.3.0:*:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r1:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r10:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r11:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r12:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r13:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r14:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r15:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r16:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r17:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r18:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r19:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r2:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r21:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r22:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r23:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r23b:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r3:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r4:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r5:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r6:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r7:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r8:*:*:*:*:*:*
- cpe:2.3:o:juniper:screenos:6.3.0:r9:*:*:*:*:*:*
- (no CPE)range: 6.3.0 prior to 6.3.0r24
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/99590nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038881nvdThird Party AdvisoryVDB Entry
- kb.juniper.net/JSA10782nvdVendor Advisory
News mentions
0No linked articles in our index yet.