CVE-2025-59974

8.4

Juniper Networks · Junos Space Security Director

A stored cross-site scripting (XSS) vulnerability in Juniper Junos Space Security Director allows authenticated attackers to inject malicious scripts that execute in other users' browser sessions.

Executive summary

A stored cross-site scripting vulnerability in Juniper Networks Junos Space Security Director poses a significant risk of session compromise for authenticated users.

Vulnerability

This is an improper neutralization of input during web page generation (CWE-79) flaw. It requires an attacker to possess high privileges to inject malicious scripts, which are then stored and executed when other users access the affected application pages.

Business impact

The CVSS score of 8.4 reflects the high potential for impact on confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute scripts in the context of other users, potentially leading to session hijacking, unauthorized administrative actions, or the theft of sensitive configuration data managed within the Security Director platform.

Remediation

Immediate Action: Update Juniper Junos Space Security Director to version 24.1R4 or any subsequent release to apply the necessary security patches.

Proactive Monitoring: Review application access logs for unusual script injections or patterns involving administrative user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict input validation and XSS filtering rules to intercept malicious payloads targeting the web interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS severity and the nature of stored XSS, organizations should prioritize upgrading their Security Director instances to version 24.1R4. Ensuring that administrative sessions are protected from script injection is critical to maintaining the integrity of the network management environment.

More Juniper Networks CVEs

Sources