PT-2006-4442 · Juniper Networks · Juniper Networks Redline Dx

Darren Bounds

·

Published

2006-07-13

·

Updated

2018-10-18

·

CVE-2006-3567

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks (Redline) DX versions 5.1.x and earlier
Description A cross-site scripting (XSS) issue exists in the web administration interface logging feature, allowing remote attackers to inject arbitrary web script or HTML via the username login field.
Recommendations For Juniper Networks (Redline) DX versions 5.1.x and earlier, consider disabling the web administration interface logging feature as a temporary workaround until a patch is available. Restrict access to the logging feature to minimize the risk of exploitation. Avoid using the username field in the login process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3567

Affected Products

Juniper Networks Redline Dx