5.4
CVSSv3

CVE-2018-0059

Published: 10/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions before 6.3.0r26.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper netscreen screenos 6.3.0r4

juniper netscreen screenos 6.3.0r6

juniper netscreen screenos 6.3.0r13

juniper netscreen screenos 6.3.0r15

juniper netscreen screenos 6.3.0r21

juniper netscreen screenos 6.3.0r23

juniper netscreen screenos 6.3.0

juniper netscreen screenos 6.3.0r1

juniper netscreen screenos 6.3.0r2

juniper netscreen screenos 6.3.0r16

juniper netscreen screenos 6.3.0r17

juniper netscreen screenos 6.3.0r18

juniper netscreen screenos 6.3.0r19

juniper netscreen screenos 6.3.0r8

juniper netscreen screenos 6.3.0r9

juniper netscreen screenos 6.3.0r10

juniper netscreen screenos 6.3.0r11

juniper netscreen screenos 6.3.0r24

juniper netscreen screenos 6.3.0r24b1

juniper netscreen screenos 6.3.0r25

juniper netscreen screenos 6.3.0r3

juniper netscreen screenos 6.3.0r5

juniper netscreen screenos 6.3.0r7

juniper netscreen screenos 6.3.0r12

juniper netscreen screenos 6.3.0r14

juniper netscreen screenos 6.3.0r22

juniper netscreen screenos 6.3.0r23b1