Junos Space Security Director: XSS vulnerability in web administration
CVE-2018-0047

8HIGH

Key Information:

Vendor
CVE Published:
10 October 2018

Badges

๐Ÿ‘พ Exploit Exists

Summary

A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of Juniper Networks Junos Space Security Director prior to 17.2R2.

Affected Version(s)

Junos Space Security Director <= 17.2R2

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Marcel Bilal of IT-Dienstleistungszentrum Berlin
.