Juniper Junos Space vulnerabilities
77 known vulnerabilities affecting juniper/junos_space.
Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH16MEDIUM51
Vulnerabilities
Page 2 of 4
CVE-2025-60001MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-60001 [MEDIUM] CWE-79 CVE-2025-60001: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue af
nvd
CVE-2025-60009MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-60009 [MEDIUM] CWE-79 CVE-2025-60009: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the
CLI Configlet
page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue a
nvd
CVE-2025-59989MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59989 [MEDIUM] CWE-79 CVE-2025-59989: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue a
nvd
CVE-2025-59990MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59990 [MEDIUM] CWE-79 CVE-2025-59990: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator.
This issue
nvd
CVE-2025-59988MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59988 [MEDIUM] CWE-79 CVE-2025-59988: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue af
nvd
CVE-2025-59982MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59982 [MEDIUM] CWE-79 CVE-2025-59982: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue a
nvd
CVE-2025-59986MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59986 [MEDIUM] CWE-79 CVE-2025-59986: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
nvd
CVE-2024-39563MEDIUMCVSS 6.9v24.12024-10-11
CVE-2024-39563 [MEDIUM] CWE-77 CVE-2024-39563: A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web application, gaining complete control of the device.
A specific script in the Junos Sp
nvd
CVE-2021-0220MEDIUMCVSS 6.8v1.0v1.1+29 more2021-01-15
CVE-2021-0220 [MEDIUM] CWE-257 CVE-2021-0220: The Junos Space Network Management Platform has been found to store shared secrets in a recoverable
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a success
nvd
CVE-2020-1611MEDIUMCVSS 6.5v17.1v17.2+7 more2020-01-15
CVE-2020-1611 [MEDIUM] CVE-2020-1611: A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all
A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target when the device receives malicious HTTP packets. This issue affects: Juniper Networks Junos Space versions prior to 19.4R1.
nvd
CVE-2019-0017HIGHCVSS 8.8v13.3v14.1+7 more2019-01-15
CVE-2019-0017 [MEDIUM] CWE-434 CVE-2019-0017: The Junos Space application, which allows Device Image files to be uploaded, has insufficient validi
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
nvd
CVE-2019-0016MEDIUMCVSS 6.5v13.3v14.1+7 more2019-01-15
CVE-2019-0016 [MEDIUM] CVE-2019-0016: A malicious authenticated user may be able to delete a device from the Junos Space database without
A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
nvd
CVE-2018-0046MEDIUMCVSS 6.1v18.1r12018-10-10
CVE-2018-0046 [HIGH] CWE-79 CVE-2018-0046: A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space
A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions. This issue affects Juniper Networks Junos Space versions prior to 18.2R1.
nvd
CVE-2018-0047MEDIUMCVSS 5.4v13.3v14.1+5 more2018-10-10
CVE-2018-0047 [HIGH] CWE-79 CVE-2018-0047: A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Dir
A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of
nvd
CVE-2014-3413CRITICALCVSS 9.8v13.32018-04-05
CVE-2014-3413 [CRITICAL] CWE-798 CVE-2014-3413: The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a h
The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access.
nvd
CVE-2018-0012HIGHCVSS 7.8≤ 17.22018-01-10
CVE-2018-0012 [HIGH] CVE-2018-0012: Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated
Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated attacker to gain root privileges.
nvd
CVE-2018-0011MEDIUMCVSS 5.4v13.3v14.1+4 more2018-01-10
CVE-2018-0011 [MEDIUM] CWE-79 CVE-2018-0011: A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote a
A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management device.
nvd
CVE-2018-0010MEDIUMCVSS 6.5v13.3v14.1+5 more2018-01-10
CVE-2018-0010 [MEDIUM] CWE-269 CVE-2018-0010: A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not hav
A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a device to reuse the URL that was created for another user to perform SSH access. Affected releases are all versions of Junos Space Security Director prior to 17.2R1.
nvd
CVE-2017-10622CRITICALCVSS 9.8v17.1v16.12017-10-13
CVE-2017-10622 [CRITICAL] CWE-287 CVE-2017-10622: An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform m
An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user. This issue only affects Junos Space Network Management Platform 17.1R1 without Patch v1 and 16.1 releases prior to 16.1R3. This issue was found by an external
nvd
CVE-2016-1265CRITICALCVSS 9.8≤ 15.1r22017-10-13
CVE-2016-1265 [CRITICAL] CWE-200 CVE-2016-1265: A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary cod
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to
nvd