cbcvebase.

Juniper Networks Junos Space vulnerabilities

49 known vulnerabilities affecting juniper_networks/junos_space.

Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH9MEDIUM38

Vulnerabilities

Page 3 of 3
CVE-2025-59990P4MEDIUMCVSS 6.1fixed in 24.1R42025-10-09
CVE-2025-59990 [MEDIUM] CWE-79 CVE-2025-59990: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issue
nvd
CVE-2025-59988P4MEDIUMCVSS 6.1fixed in 24.1R42025-10-09
CVE-2025-59988 [MEDIUM] CWE-79 CVE-2025-59988: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue af
nvd
CVE-2025-59986P4MEDIUMCVSS 6.1fixed in 24.1R42025-10-09
CVE-2025-59986 [MEDIUM] CWE-79 CVE-2025-59986: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
nvd
CVE-2017-2310P4MEDIUMCVSS 5.3vversions prior to 16.1R12017-05-30
CVE-2017-2310 [MEDIUM] CVE-2017-2310: A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
nvd
CVE-2018-0046P4MEDIUMCVSS 6.1≥ unspecified, < 18.2R12018-10-10
CVE-2018-0046 [MEDIUM] CWE-79 CVE-2018-0046: A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions. This issue affects Juniper Networks Junos Space versions prior to 18.2R1.
nvd
CVE-2025-59984P4MEDIUMCVSS 6.1fixed in 24.1R42025-10-09
CVE-2025-59984 [MEDIUM] CWE-79 CVE-2025-59984: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all ve
nvd
CVE-2017-2307P4MEDIUMCVSS 6.1vversions prior to 16.1R12017-05-30
CVE-2017-2307 [MEDIUM] CWE-79 CVE-2017-2307: A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks J A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.
nvd
CVE-2018-0011P4MEDIUMCVSS 5.4≥ All, < 17.2R12018-01-10
CVE-2018-0011 [MEDIUM] CWE-79 CVE-2018-0011: A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote a A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management device.
nvd
CVE-2020-1652MEDIUMCVSS 5.6≥ 20.1, < 20.1R12020-07-17
CVE-2020-1652 [MEDIUM] CWE-213 Junos Space: OpenNMS is accessible via port 9443 Junos Space: OpenNMS is accessible via port 9443 OpenNMS is accessible via port 9443
cvelistv5
Juniper Networks Junos Space vulnerabilities | cvebase