cbcvebase.

Juniper Junos Space vulnerabilities

92 known vulnerabilities affecting juniper/junos_space.

Total CVEs
92
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH21MEDIUM61

Vulnerabilities

Page 2 of 5
CVE-2025-60002MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-60002 [MEDIUM] CWE-79 CVE-2025-60002: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This iss
nvdjuniper
CVE-2025-59999MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59999 [MEDIUM] CWE-79 CVE-2025-59999: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the API Access Profiles page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issu
nvdjuniper
CVE-2025-60001MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-60001 [MEDIUM] CWE-79 CVE-2025-60001: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue af
nvdjuniper
CVE-2025-59998MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59998 [MEDIUM] CWE-79 CVE-2025-59998: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Archive Log screen that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affe
nvdjuniper
CVE-2025-59993MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59993 [MEDIUM] CWE-79 CVE-2025-59993: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Space Node Setting fields that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issu
nvdjuniper
CVE-2025-59992MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59992 [MEDIUM] CWE-79 CVE-2025-59992: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Secure Console page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue aff
nvdjuniper
CVE-2025-59986MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59986 [MEDIUM] CWE-79 CVE-2025-59986: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
nvdjuniper
CVE-2025-59990MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59990 [MEDIUM] CWE-79 CVE-2025-59990: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issue
nvdjuniper
CVE-2025-59985MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59985 [MEDIUM] CWE-79 CVE-2025-59985: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
nvdjuniper
CVE-2025-59988MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59988 [MEDIUM] CWE-79 CVE-2025-59988: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue af
nvdjuniper
CVE-2025-59982MEDIUMCVSS 5.1fixed in 24.1v24.12025-10-09
CVE-2025-59982 [MEDIUM] CWE-79 CVE-2025-59982: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue a
nvdjuniper
CVE-2024-39563MEDIUMCVSS 6.9v24.12024-10-11
CVE-2024-39563 [MEDIUM] CWE-77 CVE-2024-39563: A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web application, gaining complete control of the device. A specific script in the Junos Sp
nvdjuniper
CVE-2024-47508MEDIUMCVSS 6.52024-10-11
CVE-2024-47508 [MEDIUM] CWE-770 CVE-2024-47508: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved CVE-2024-47508: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).When specific SNMP GET operat
juniper
CVE-2024-47509MEDIUMCVSS 6.52024-10-11
CVE-2024-47509 [MEDIUM] CWE-770 CVE-2024-47509: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved CVE-2024-47509: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).When specific SNMP GET operat
juniper
CVE-2024-47505MEDIUMCVSS 6.52024-10-11
CVE-2024-47505 [MEDIUM] CWE-770 CVE-2024-47505: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved CVE-2024-47505: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).When specific SNMP GET operat
juniper
CVE-2023-22400HIGHCVSS 7.52023-01-13
CVE-2023-22400 [HIGH] CWE-400 CVE-2023-22400: An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthent CVE-2023-22400: An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or a specif
juniper
CVE-2022-22211HIGHCVSS 7.52022-10-18
CVE-2022-22211 [HIGH] CWE-770 CVE-2022-22211: A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to c CVE-2022-22211: A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Continuously polling the SNMP jnxCosQstatTable causes the FPC to run out of GUID space, causing a Denial of
juniper
CVE-2022-22215MEDIUMCVSS 6.52022-07-20
CVE-2022-22215 [MEDIUM] CWE-772 CVE-2022-22215: A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Juno CVE-2022-22215: A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). It is possibl
juniper
CVE-2021-0293MEDIUMCVSS 5.52021-07-15
CVE-2021-0293 [MEDIUM] CWE-401 CVE-2021-0293: A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lifetime leads to a memory leak each time the CLI com CVE-2021-0293: A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lifetime leads to a memory leak each time the CLI command 'show system connections extensive' is executed. The amount of memory leaked on each execution depends on the number of TCP connectio
juniper
CVE-2021-0238MEDIUMCVSS 5.52021-04-22
CVE-2021-0238 [MEDIUM] CWE-400 CVE-2021-0238: When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may caus CVE-2021-0238: When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may cause the system to run out of disk space, excessive disk usage may cause other complications. An administrator can use the following CLI comm
juniper