CVE-2018-0059

UnknownEPSS 0.80%

Last modified

CVE-2018-0059 is a vulnerability of currently unknown severity. A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.

Description

A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.

Metrics

EPSS Probability
0.80%

52.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JuniperNetscreen Screenos6.3.0
JuniperNetscreen Screenos6.3.0r1
JuniperNetscreen Screenos6.3.0r2
JuniperNetscreen Screenos6.3.0r3
JuniperNetscreen Screenos6.3.0r4
JuniperNetscreen Screenos6.3.0r5
JuniperNetscreen Screenos6.3.0r6
JuniperNetscreen Screenos6.3.0r7
JuniperNetscreen Screenos6.3.0r8
JuniperNetscreen Screenos6.3.0r9
JuniperNetscreen Screenos6.3.0r10
JuniperNetscreen Screenos6.3.0r11
JuniperNetscreen Screenos6.3.0r12
JuniperNetscreen Screenos6.3.0r13
JuniperNetscreen Screenos6.3.0r14
JuniperNetscreen Screenos6.3.0r15
JuniperNetscreen Screenos6.3.0r16
JuniperNetscreen Screenos6.3.0r17
JuniperNetscreen Screenos6.3.0r18
JuniperNetscreen Screenos6.3.0r19
JuniperNetscreen Screenos6.3.0r21
JuniperNetscreen Screenos6.3.0r22
JuniperNetscreen Screenos6.3.0r23
JuniperNetscreen Screenos6.3.0r23b1
JuniperNetscreen Screenos6.3.0r24
JuniperNetscreen Screenos6.3.0r24b1
JuniperNetscreen Screenos6.3.0r25

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-0059?
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.
How severe is CVE-2018-0059?
Severity scoring for CVE-2018-0059 is pending analysis. The EPSS model estimates a 0.80% probability of exploitation in the next 30 days.
How do I fix CVE-2018-0059?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-0059?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST