cbcvebase.
CVE-2017-10612
published 2017-10-13

CVE-2017-10612: A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or…

PriorityP335high8CVSS 3.0
AVNACLPRLUIRSUCHIHAH
EPSS
1.29%
67.0th percentile
A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.

Affected

4 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniperjunos_space<= 16.1r3
juniperjunos_space
juniper_networksjunos_space

CVSS provenance

nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.