PT-2025-41433 · Juniper Networks · Junos Space

CVE-2025-59997

·

Published

2025-10-09

·

Updated

2025-10-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos Space versions prior to 24.1R4
Description An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') issue exists in Juniper Networks Junos Space. An attacker can inject script tags in the CLI Configlets pages. When another user visits these pages, the attacker can execute commands with the target's permissions, potentially including administrator privileges.
Recommendations Update to Junos Space version 24.1R4 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59997

Affected Products

Junos Space