
CVE-2021-0220 – Junos Space: Shared secrets stored in recoverable format and directly exposed through the UI
https://notcve.org/view.php?id=CVE-2021-0220
15 Jan 2021 — The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a successful attack includes, but is not limited to, obtaining access to other servers connected to the Junos Space Management Platform. This issue affects Juniper Net... • https://kb.juniper.net/JSA11110 • CWE-257: Storing Passwords in a Recoverable Format CWE-522: Insufficiently Protected Credentials •

CVE-2018-0012 – Junos Space: Local privilege escalation vulnerability in Junos Space
https://notcve.org/view.php?id=CVE-2018-0012
10 Jan 2018 — Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated attacker to gain root privileges. Junos Space se ve afectado por una vulnerabilidad de escalado de privilegios que podría permitir que un atacante local autenticado obtenga privilegios root. • http://www.securitytracker.com/id/1040189 •

CVE-2016-1265 – Junos Space: privilege escalation vulnerabilities in Junos Space
https://notcve.org/view.php?id=CVE-2016-1265
13 Oct 2017 — A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected. Un atacante remoto no autenticado en una red con acceso a Junos Space podría ejecutar código arbitrario en Junos Space u obtener acceso a d... • https://kb.juniper.net/JSA10727 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-255: Credentials Management Errors CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2017-10612 – Junos Space: Persistent Cross site scripting in Junos Space
https://notcve.org/view.php?id=CVE-2017-10612
13 Oct 2017 — A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1. Una vulnerabilidad de Site Scripting persistente en Juniper Networks Junos Space permite a los usuarios que pueden cambiar determinadas configuraciones implantar c... • http://www.securityfocus.com/bid/101256 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-10623 – Junos Space: Insufficient verification of cluster messages
https://notcve.org/view.php?id=CVE-2017-10623
13 Oct 2017 — Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1. Falta de autenticación y autorización de mensajes de clústeres en Juniper Networks Junos Space podría permitir que un tipo de atacante Man-in-the-Middle (MitM) intercepte, inyecte o interrumpa las operaciones ... • https://kb.juniper.net/JSA10826 • CWE-287: Improper Authentication •

CVE-2017-10624 – Junos Space: Insufficient verification of node certificates.
https://notcve.org/view.php?id=CVE-2017-10624
13 Oct 2017 — Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1. Verificación insuficiente de los certificados de los nodos en Juniper Networks Junos Space puede permitir que un tipo de atacante Man-in-the-Middle (MitM) realice modificaciones no autorizadas a la base de datos Space o añada nodos. Las d... • http://www.securityfocus.com/bid/101255 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2017-2305
https://notcve.org/view.php?id=CVE-2017-2305
30 May 2017 — On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation. En versiones de Juniper Networks Junos Space anteriores a 16.1R1, debido a una insuficiente verificación de autorización, los usuarios de sólo lectura en la interfaz web de gestión de Junos Space, pueden crear usuarios privilegiados, lo que permite la escalada de privilegios. • http://www.securityfocus.com/bid/98759 • CWE-863: Incorrect Authorization •

CVE-2017-2306
https://notcve.org/view.php?id=CVE-2017-2306
30 May 2017 — On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device. En versiones de Juniper Networks Junos Space anteriores a 16.1R1, debido a una insuficiente verificación de autorización, los usuarios de sólo lectura de la interfaz web de gestión de Junos Space, pueden ejecutar código en el dispositivo. • http://www.securityfocus.com/bid/98772 • CWE-863: Incorrect Authorization •

CVE-2017-2307
https://notcve.org/view.php?id=CVE-2017-2307
30 May 2017 — A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space. Una vulnerabilidad XSS de tipo reflejado en la interfaz de administración de Junos Space de Juniper Networks en versiones anteriores a 16.1R1, puede permitir a atacantes remotos robar información confidencial o realizar ciertas acciones administrativas en Juno... • http://www.securityfocus.com/bid/98749 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-2308
https://notcve.org/view.php?id=CVE-2017-2308
30 May 2017 — An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device. Una vulnerabilidad de inyección de tipo XML External Entity en Junos Space anterior a versión 16.1R1 de Juniper Networks, puede permitir a un usuario autenticado leer archivos arbitrarios en el dispositivo. • http://www.securityfocus.com/bid/98755 • CWE-611: Improper Restriction of XML External Entity Reference •