← Back

CVE-2018-0059

nvd nist
Published: Oct 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.

Affected (27)

1 product
Netscreen Screenos
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Version 6.3.0
Version 6.3.0r10
Version 6.3.0r11
Version 6.3.0r12
Version 6.3.0r13
Version 6.3.0r14
Version 6.3.0r15
Version 6.3.0r16
Version 6.3.0r17
Version 6.3.0r18
Version 6.3.0r19
Version 6.3.0r1
Version 6.3.0r21
Version 6.3.0r22
Version 6.3.0r23
Version 6.3.0r23b1
Version 6.3.0r24
Version 6.3.0r24b1
Version 6.3.0r25
Version 6.3.0r2
Version 6.3.0r3
Version 6.3.0r4
Version 6.3.0r5
Version 6.3.0r6
Version 6.3.0r7
Version 6.3.0r8
Version 6.3.0r9

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.