← back
CVE-2025-59974

Junos Space Security Director: Persistent Cross-Site Scripting (XSS) vulnerability

CVSS 9.3 CRITICALEPSS 0.3%CWE-79
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
09 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers when they access affected pages.This issue affects Juniper Security Director:  * All versions before 24.1R4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:C/RE:M/U:Amber

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →