Database/Firmware, BMC & network fabric
Junos Space: stored XSS in management UI pages lets an attacker run actions as a logged-in administrator
Impact
Junos Space is the management platform for Juniper switching and routing, including datacenter fabric. Script injected into the template creation page or the Generate Report page executes when another operator views it, letting the attacker act with that operator's permissions - and if the viewer is an administrator, that means driving fabric configuration changes through the authenticated session. Juniper assigned two ids for the same stored-XSS class in two pages of the same product, with one advisory and one fixed release; they are recorded here as one issue. Exploitation needs an operator to open the poisoned page, which is why the scored impact stays moderate rather than a straight fabric takeover.
Who can reach it
Network access to the Junos Space web UI - typically the management VLAN. The record reports no authentication requirement for the injection (PR:N) but does require a second user, ideally an administrator, to visit the affected page (UI:A).
What to do
Upgrade Junos Space to 24.1R4 or later; all earlier versions are affected per JSA103140. This is a management-application upgrade - plan a Junos Space maintenance window and service restart - and does not touch switch firmware, so the fabric data plane keeps forwarding. Until the upgrade, restrict Junos Space UI reachability to trusted admin networks and review existing templates and report definitions for injected content.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalationCVE-2026-24166 · NVIDIA UFM Enterprise (session management, hard-coded cryptographic key)Medium
- IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES keyCVE-2026-4936 · IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM, FW950 / FW1060 / FW1110Medium
- OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodesCVE-2024-42934 · OpenIPMI before 2.0.36Medium
- Dell SmartFabric OS10: command injection lets a high-privileged remote user run arbitrary OS commandsCVE-2026-35160 · Dell SmartFabric OS10 (switch NOS command handling)Medium
- Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageCVE-2018-9279 · Eaton UPS 9PX 8000 SP web interfaceMedium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.