CVE-2018-0059: ScreenOS: Stored Cross-Site Scripting (XSS) vulnerability
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0059?
CVE-2018-0059 has a medium severity rating due to its potential to allow cross-site scripting attacks that can compromise sensitive information.
How do I fix CVE-2018-0059?
To fix CVE-2018-0059, you should upgrade your Juniper NetScreen ScreenOS to version 6.3.0r26 or later.
What type of vulnerability is CVE-2018-0059?
CVE-2018-0059 is a persistent cross-site scripting vulnerability that can allow unauthorized script injection.
Who is affected by CVE-2018-0059?
CVE-2018-0059 affects remote authenticated users of the Juniper NetScreen ScreenOS versions 6.3.0 through 6.3.0r25.
What are the potential risks of CVE-2018-0059?
The risks associated with CVE-2018-0059 include the potential for attackers to steal sensitive data and credentials during web administration sessions.