← Vulnerability feed

Vulnerability record · CVE-2017-2337 · published 17 July 2017

CVE-2017-2337: Juniper screenos cross-site scripting vulnerability

Juniper · Screenos

A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue.

5.4 CVSS 3.0 Medium EPSS 1.1% · top 36.4% CWE-79 · Cross-site scripting
5.4CVSS 3.0 base score, v2 3.5
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute commands with the permissions of an administrator. This issue affects Juniper Networks ScreenOS 6.3.0 releases prior to 6.3.0r24 on SSG Series. No other Juniper Networks products or platforms are affected by this issue.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/99590 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038881 Third Party AdvisoryVDB Entry
https://kb.juniper.net/JSA10782 Vendor Advisory
http://www.securityfocus.com/bid/99590 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038881 Third Party AdvisoryVDB Entry
https://kb.juniper.net/JSA10782 Vendor Advisory

Track CVE-2017-2337 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-7755Juniper ScreenOS improper authentication grants admin accessJuniper ScreenOS contains an improper authentication flaw (CWE-287) where entering an unspecified password during an SSH or TELNET session grants adm…KEVEPSS 61%analysed8.1CVE-2015-7754Juniper screenos improper input validation vulnerabilityJuniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or exec…EPSS 3.9%7.8CVE-2014-3813Juniper screenos vulnerabilityUnspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lo…EPSS 1.3%7.8CVE-2014-3814Juniper screenos improper input validation vulnerabilityThe Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote att…EPSS 1.3%7.8CVE-2014-2842Juniper screenos vulnerabilityJuniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.EPSS 3.5%7.5CVE-2016-1268Juniper screenos improper input validation vulnerabilityThe administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a cra…EPSS 1.9%7.1CVE-2013-6958Juniper screenos vulnerabilityJuniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of…EPSS 1.9%6.5CVE-2018-0014Juniper screenos information exposure vulnerabilityJuniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from p…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2017-2337), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.