GPU VulnDB

Database/Firmware, BMC & network fabric

Junos Space: stored XSS in management UI pages lets an attacker run actions as a logged-in administrator

CVSS 5.1CVE-2025-59990Firmware, BMC & network fabric+1 more CVEscurated

Impact

Junos Space is the management platform for Juniper switching and routing, including datacenter fabric. Script injected into the template creation page or the Generate Report page executes when another operator views it, letting the attacker act with that operator's permissions - and if the viewer is an administrator, that means driving fabric configuration changes through the authenticated session. Juniper assigned two ids for the same stored-XSS class in two pages of the same product, with one advisory and one fixed release; they are recorded here as one issue. Exploitation needs an operator to open the poisoned page, which is why the scored impact stays moderate rather than a straight fabric takeover.

Who can reach it

Network access to the Junos Space web UI - typically the management VLAN. The record reports no authentication requirement for the injection (PR:N) but does require a second user, ideally an administrator, to visit the affected page (UI:A).

What to do

Upgrade Junos Space to 24.1R4 or later; all earlier versions are affected per JSA103140. This is a management-application upgrade - plan a Junos Space maintenance window and service restart - and does not touch switch firmware, so the fabric data plane keeps forwarding. Until the upgrade, restrict Junos Space UI reachability to trusted admin networks and review existing templates and report definitions for injected content.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2025-60001

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.