Juniper Junos Space vulnerabilities
78 known vulnerabilities affecting juniper/junos_space.
Total CVEs
78
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH15MEDIUM53
Vulnerabilities
Page 1 of 4
CVE-2016-1265P2CRITICALCVSS 9.8≤ 15.1r22017-10-13
CVE-2016-1265 [CRITICAL] CWE-200 CVE-2016-1265: A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary cod
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to
nvd
CVE-2017-10622P2CRITICALCVSS 9.8v17.1v16.12017-10-13
CVE-2017-10622 [CRITICAL] CWE-287 CVE-2017-10622: An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform m
An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user. This issue only affects Junos Space Network Management Platform 17.1R1 without Patch v1 and 16.1 releases prior to 16.1R3. This issue was found by an external
nvd
CVE-2014-3412P2CRITICALCVSS 10.0≤ 13.1v1.0+12 more2014-05-20
CVE-2014-3412 [CRITICAL] CVE-2014-3412: Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, all
Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary commands via unspecified vectors.
nvd
CVE-2016-4926P2CRITICALCVSS 9.8≤ 15.22017-03-20
CVE-2016-4926 [CRITICAL] CWE-287 CVE-2016-4926: Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based u
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.
nvd
CVE-2016-4929P3HIGHCVSS 8.8≤ 15.22017-03-20
CVE-2016-4929 [HIGH] CWE-77 CVE-2016-4929: Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary c
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
nvd
CVE-2014-0429P3CRITICALCVSS 10.0fixed in 15.12014-04-16
CVE-2014-0429 [CRITICAL] CVE-2014-0429: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1;
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2014-0456P3CRITICALCVSS 10.0fixed in 15.12014-04-16
CVE-2014-0456 [CRITICAL] CVE-2014-0456: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2014-2421P3CRITICALCVSS 10.0fixed in 15.12014-04-16
CVE-2014-2421 [CRITICAL] CVE-2014-2421: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Em
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2014-3413P3CRITICALCVSS 9.8v13.32018-04-05
CVE-2014-3413 [CRITICAL] CWE-798 CVE-2014-3413: The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a h
The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access.
nvd
CVE-2014-0457P3CRITICALCVSS 10.0fixed in 15.12014-04-16
CVE-2014-0457 [CRITICAL] CVE-2014-0457: Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.
Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2015-3209P3HIGHCVSS 7.5≤ 15.12015-06-15
CVE-2015-3209 [HIGH] CWE-787 CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitr
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
nvd
CVE-2024-39563P3HIGHCVSS 7.3v24.12024-10-11
CVE-2024-39563 [HIGH] CWE-77 CVE-2024-39563: A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web application, gaining complete control of the device.
A specific script in the Junos Spac
nvd
CVE-2017-2306P3HIGHCVSS 8.8≤ 16.12017-05-30
CVE-2017-2306 [HIGH] CWE-863 CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
nvd
CVE-2025-59975P3HIGHCVSS 7.5fixed in 22.2v22.2+1 more2025-10-09
CVE-2025-59975 [HIGH] CWE-400 CVE-2025-59975: An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Ju
An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading to a Denial of Service (DoS).
After continuously flooding the system with inbound connection requests,
nvd
CVE-2017-2305P3HIGHCVSS 8.8≤ 16.12017-05-30
CVE-2017-2305 [HIGH] CWE-863 CVE-2017-2305: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
nvd
CVE-2025-59978P3CRITICALCVSS 9.0fixed in 24.1v24.12025-10-09
CVE-2025-59978 [CRITICAL] CWE-79 CVE-2025-59978: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions.
This issue affects all versions o
nvd
CVE-2019-0017P3HIGHCVSS 8.8v13.3-r1v13.3-r2+21 more2019-01-15
CVE-2019-0017 [HIGH] CWE-434 CVE-2019-0017: The Junos Space application, which allows Device Image files to be uploaded, has insufficient validi
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
nvd
CVE-2014-6500P3HIGHCVSS 7.5≤ 15.12014-10-15
CVE-2014-6500 [HIGH] CVE-2014-6500: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.
nvd
CVE-2014-6491P3HIGHCVSS 7.5≤ 15.12014-10-15
CVE-2014-6491 [HIGH] CVE-2014-6491: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.
nvd
CVE-2025-59976P3MEDIUMCVSS 6.5fixed in 24.1v24.12025-10-09
CVE-2025-59976 [MEDIUM] CWE-552 CVE-2025-59976: An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an attacker can gain access to files beyond the file path normally allowed by the JBoss daemon. These files
nvd
1 / 4Next →