// For flags

CVE-2018-0059

ScreenOS: Stored Cross-Site Scripting (XSS) vulnerability

Severity Score

5.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.

Una vulnerabilidad Cross-Site Scripting (XSS) persistente en la interfaz gráfica de usuario de ScreenOS podría permitir que un usuario autenticado remoto inyecte scripts web o HTML y robe datos sensibles y credenciales de una sesión de administración web, posiblemente engañando a un usuario administrativo Las versiones afectadas son Juniper Networks ScreenOS 6.3.0 en versiones anteriores a la 6.3.0r26.

*Credits: Marcel Bilal from IT-Dienstleistungszentrum Berlin
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-16 CVE Reserved
  • 2018-10-10 CVE Published
  • 2024-08-19 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
https://kb.juniper.net/JSA10894 2019-10-09
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r1
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r1"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r2
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r2"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r3
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r3"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r4
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r4"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r5
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r5"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r6
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r6"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r7
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r7"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r8
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r8"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r9
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r9"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r10
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r10"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r11
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r11"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r12
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r12"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r13
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r13"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r14
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r14"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r15
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r15"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r16
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r16"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r17
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r17"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r18
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r18"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r19
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r19"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r21
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r21"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r22
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r22"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r23
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r23"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r23b1
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r23b1"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r24
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r24"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r24b1
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r24b1"
-
Affected
Juniper
Search vendor "Juniper"
Netscreen Screenos
Search vendor "Juniper" for product "Netscreen Screenos"
6.3.0r25
Search vendor "Juniper" for product "Netscreen Screenos" and version "6.3.0r25"
-
Affected