An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers when they access affected pages.This issue affects Juniper Security Director: * All versions before 24.1R4.
An attacker with administrator privileges injects malicious JavaScript code into the application, which is permanently stored (stored XSS). When other users visit pages affected by the vulnerability, the browser automatically executes the stored script in the context of their session. This can lead to session theft, interception of authentication data, or execution of unauthorized actions on behalf of the victim. The vulnerability results from improper neutralization of input data during web page content generation (CWE-79).
An attacker can hijack sessions of other users, steal authentication credentials, and in the case of victims with elevated privileges — gain broad access to network security management functions. High impact on confidentiality, integrity, and availability in both the system context and dependent environment indicates the possibility of serious, cascading consequences.
Juniper Space Security Director should be updated to version 24.1R4 or later. Details available in the vendor's guide: https://supportportal.juniper.net/JSA103139
Juniper Space Security Director — all versions before 24.1R4
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:AmberJuniper Space Security Director
APPJuniper24.1< 24.1
Related vulnerabilities
A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthen...
RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)
Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)
Słabe wymagania hasła w Juniper Networks CTP OS — przejęcie urządzenia
Domyślne hasło w Juniper Networks vLWC umożliwia przejęcie urządzenia