CVE-2014-3824 describes a cross-site scripting (XSS) vulnerability in the web server component of Juniper Junos Pulse Secure Access Service (SSL VPN) devices running specific versions of IVE OS. This flaw allows remote, unauthenticated attackers to inject arbitrary web script or HTML into affected systems. With a CVSS score of 4.3, it is considered a medium-severity vulnerability, requiring moderate attack complexity and primarily impacting data integrity through client-side script execution. There is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1:*:*:*:*:*:*:* | ||
7.1r1CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r1:*:*:*:*:*:*:* | ||
7.1r1.1CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r1.1:*:*:*:*:*:*:* | ||
7.1r2CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r2:*:*:*:*:*:*:* | ||
7.1r3CPE matchmatch criteria | cpe:2.3:a:juniper:junos_pulse_secure_access_service:7.1r3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.