CVE-2014-3824: Juniper Junos Pulse Secure Access Service
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- Juniper Junos Pulse Secure Access Service: version 7.1 only; version 7.1r1 only; version 7.1r1.1 only; version 7.1r2 only; version 7.1r3 only; version 7.1r4 only; …
Published 2014-09-29. Last modified 2026-06-17.