CVE-2018-0011

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/01/2018
Last modified:
09/10/2019

Description

A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juniper:junos_space:13.3:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:13.3:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:13.3:r4:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:14.1:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:14.1:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:14.1:r3:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:15.1:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:15.1:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:15.1:r3:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:15.2:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:15.2:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:16.1:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:16.1:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:16.1:r3:*:*:*:*:*:*
cpe:2.3:a:juniper:junos_space:17.1:r1:*:*:*:*:*:*