9.3
CVSSv2

CVE-2021-0275

Published: 22/04/2021 Updated: 18/01/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A Cross-site Scripting (XSS) vulnerability in J-Web on Juniper Networks Junos OS allows an malicious user to target another user's session thereby gaining access to the users session. The other user session must be active for the attack to succeed. Once successful, the attacker has the same privileges as the user. If the user has root privileges, the attacker may be able to gain full control of the device. This issue affects: Juniper Networks Junos OS: 12.3 versions before 12.3R12-S15 on EX Series; 12.3X48 versions before 12.3X48-D95 on SRX Series; 15.1 versions before 15.1R7-S6 on EX Series; 15.1X49 versions before 15.1X49-D200 on SRX Series; 16.1 versions before 16.1R7-S7; 16.2 versions before 16.2R2-S11, 16.2R3; 17.1 versions before 17.1R2-S11, 17.1R3-S2; 17.2 versions before 17.2R3-S3; 17.3 versions before 17.3R2-S5, 17.3R3-S7; 17.4 versions before 17.4R2-S9, 17.4R3; 18.1 versions before 18.1R3-S9; 18.2 versions before 18.2R2-S7, 18.2R3-S3; 18.3 versions before 18.3R1-S7, 18.3R2-S3, 18.3R3-S1; 18.4 versions before 18.4R1-S6, 18.4R2-S4, 18.4R3; 19.1 versions before 19.1R2-S1, 19.1R3; 19.2 versions before 19.2R1-S3, 19.2R2; 19.3 versions before 19.3R2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 12.3

juniper junos 15.1

juniper junos 12.3x48

juniper junos 15.1x49

juniper junos 16.1

juniper junos 16.2

juniper junos 17.1

juniper junos 17.2

juniper junos 17.3

juniper junos 17.4

juniper junos 18.1

juniper junos 18.2

juniper junos 18.3

juniper junos 18.4

juniper junos 19.1

juniper junos 19.2

juniper junos 19.3