CRITICAL🇵🇱 Wersja polska

CVE-2025-59974

CVSS 9.3v4.0pub. 2025-10-09upd. 2026-01-23

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers when they access affected pages.This issue affects Juniper Security Director:  * All versions before 24.1R4.

🤖 AI Analysis
How it works

An attacker with administrator privileges injects malicious JavaScript code into the application, which is permanently stored (stored XSS). When other users visit pages affected by the vulnerability, the browser automatically executes the stored script in the context of their session. This can lead to session theft, interception of authentication data, or execution of unauthorized actions on behalf of the victim. The vulnerability results from improper neutralization of input data during web page content generation (CWE-79).

Impact

An attacker can hijack sessions of other users, steal authentication credentials, and in the case of victims with elevated privileges — gain broad access to network security management functions. High impact on confidentiality, integrity, and availability in both the system context and dependent environment indicates the possibility of serious, cascading consequences.

Mitigation & patch

Juniper Space Security Director should be updated to version 24.1R4 or later. Details available in the vendor's guide: https://supportportal.juniper.net/JSA103139

Who is affected

Juniper Space Security Director — all versions before 24.1R4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
  • Juniper Space Security Director

    APP
    Juniper
    24.1< 24.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-59968HIGH7.7same product

A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthen...

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2015-7755CRITICAL9.8⚠ KEVPL ✓same vendor

Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)

CVE-2026-33771CRITICAL9.1PL ✓same vendor

Słabe wymagania hasła w Juniper Networks CTP OS — przejęcie urządzenia

CVE-2026-33784CRITICAL9.3PL ✓same vendor

Domyślne hasło w Juniper Networks vLWC umożliwia przejęcie urządzenia