5.4

CVE-2018-0059

A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperNetscreen Screenos Version6.3.0
JuniperNetscreen Screenos Version6.3.0r1
JuniperNetscreen Screenos Version6.3.0r2
JuniperNetscreen Screenos Version6.3.0r3
JuniperNetscreen Screenos Version6.3.0r4
JuniperNetscreen Screenos Version6.3.0r5
JuniperNetscreen Screenos Version6.3.0r6
JuniperNetscreen Screenos Version6.3.0r7
JuniperNetscreen Screenos Version6.3.0r8
JuniperNetscreen Screenos Version6.3.0r9
JuniperNetscreen Screenos Version6.3.0r10
JuniperNetscreen Screenos Version6.3.0r11
JuniperNetscreen Screenos Version6.3.0r12
JuniperNetscreen Screenos Version6.3.0r13
JuniperNetscreen Screenos Version6.3.0r14
JuniperNetscreen Screenos Version6.3.0r15
JuniperNetscreen Screenos Version6.3.0r16
JuniperNetscreen Screenos Version6.3.0r17
JuniperNetscreen Screenos Version6.3.0r18
JuniperNetscreen Screenos Version6.3.0r19
JuniperNetscreen Screenos Version6.3.0r21
JuniperNetscreen Screenos Version6.3.0r22
JuniperNetscreen Screenos Version6.3.0r23
JuniperNetscreen Screenos Version6.3.0r23b1
JuniperNetscreen Screenos Version6.3.0r24
JuniperNetscreen Screenos Version6.3.0r24b1
JuniperNetscreen Screenos Version6.3.0r25
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.296
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
sirt@juniper.net 5.4 2.3 2.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.