Juniper Networks Junos Space vulnerabilities
49 known vulnerabilities affecting juniper_networks/junos_space.
Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM37
Vulnerabilities
Page 1 of 3
CVE-2026-21904MEDIUMCVSS 5.1fixed in 24.1R5 Patch V32026-04-09
CVE-2026-21904 [MEDIUM] CWE-79 CVE-2026-21904: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the
list filter field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue aff
cvelistv5nvd
CVE-2026-21907HIGHCVSS 8.2fixed in 24.1R52026-01-15
CVE-2026-21907 [HIGH] CWE-327 CVE-2026-21907: A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Ne
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space allows the use of static key ciphers (ssl-static-key-ciphers), reducing the confidentiality of on-path traffic communicated across the connection. These ciphers also do not support Perfect Forward Secrecy (PFS), affecting the long-ter
cvelistv5nvd
CVE-2025-59978CRITICALCVSS 9.4fixed in 24.1R42025-10-09
CVE-2025-59978 [CRITICAL] CWE-79 CVE-2025-59978: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions.
This issue affects all versions o
cvelistv5nvd
CVE-2025-59976HIGHCVSS 7.1fixed in 24.1R32025-10-09
CVE-2025-59976 [HIGH] CWE-552 CVE-2025-59976: An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an attacker can gain access to files beyond the file path normally allowed by the JBoss daemon. These files co
cvelistv5nvd
CVE-2025-59975HIGHCVSS 8.7fixed in 22.2R1 Patch V3≥ 23.1, < 23.1R1 Patch V32025-10-09
CVE-2025-59975 [HIGH] CWE-400 CVE-2025-59975: An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Ju
An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading to a Denial of Service (DoS).
After continuously flooding the system with inbound connection requests,
cvelistv5nvd
CVE-2025-59991MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59991 [MEDIUM] CWE-79 CVE-2025-59991: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Management pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator.
This issue
cvelistv5nvd
CVE-2025-59986MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59986 [MEDIUM] CWE-79 CVE-2025-59986: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
cvelistv5nvd
CVE-2025-59983MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59983 [MEDIUM] CWE-79 CVE-2025-59983: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affe
cvelistv5nvd
CVE-2025-59987MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59987 [MEDIUM] CWE-79 CVE-2025-59987: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the arbitrary device search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
cvelistv5nvd
CVE-2025-60002MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-60002 [MEDIUM] CWE-79 CVE-2025-60002: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This iss
cvelistv5nvd
CVE-2025-59989MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59989 [MEDIUM] CWE-79 CVE-2025-59989: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue a
cvelistv5nvd
CVE-2025-59996MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59996 [MEDIUM] CWE-79 CVE-2025-59996: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Configuration View page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue
cvelistv5nvd
CVE-2025-60009MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-60009 [MEDIUM] CWE-79 CVE-2025-60009: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the
CLI Configlet
page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue a
cvelistv5nvd
CVE-2025-59981MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59981 [MEDIUM] CWE-79 CVE-2025-59981: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.Thi
cvelistv5nvd
CVE-2025-59984MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59984 [MEDIUM] CWE-79 CVE-2025-59984: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all ve
cvelistv5nvd
CVE-2025-59995MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59995 [MEDIUM] CWE-79 CVE-2025-59995: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue aff
cvelistv5nvd
CVE-2025-59994MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59994 [MEDIUM] CWE-79 CVE-2025-59994: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue aff
cvelistv5nvd
CVE-2025-59982MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59982 [MEDIUM] CWE-79 CVE-2025-59982: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue a
cvelistv5nvd
CVE-2025-59992MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59992 [MEDIUM] CWE-79 CVE-2025-59992: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Secure Console page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue aff
cvelistv5nvd
CVE-2025-59997MEDIUMCVSS 5.1fixed in 24.1R42025-10-09
CVE-2025-59997 [MEDIUM] CWE-79 CVE-2025-59997: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlets pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator.
This issue aff
cvelistv5nvd
1 / 3Next →