CVE-2025-52987: Paragon Automation: A clickjacking vulnerability in the web server configuration has been addressed
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control.
This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52987?
CVE-2025-52987 is classified as a medium severity vulnerability.
How do I fix CVE-2025-52987?
To fix CVE-2025-52987, ensure that you configure the web server to include appropriate X-Frame-Options headers.
What systems are affected by CVE-2025-52987?
CVE-2025-52987 affects Juniper Networks Paragon Automation versions up to 24.1.1.
What type of vulnerability is CVE-2025-52987?
CVE-2025-52987 is a clickjacking vulnerability.
What risk does CVE-2025-52987 pose?
CVE-2025-52987 poses a risk of unauthorized actions being performed by users due to the lack of frame options.