CVE-2015-3005: Juniper Junos
Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- Juniper Junos: version 12.1x44 only; version 12.1x46 only; version 12.1x47 only; version 12.1x48 only
Published 2015-04-10. Last modified 2026-06-17.