[CIVN-2025-0255] Multiple Cross-Site Scripting Vulnerabilities in Junos Space
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Cross-Site Scripting Vulnerabilities in Junos Space
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Juniper Networks Junos Space versions prior to 24.1R4.
Overview
Multiple Cross-site Scripting vulnerabilities have been reported in Junos space which could allow the attacker to perform cross-site scripting (XSS) attacks.
Target Audience:
All organizations and individuals using the affected Juniper Junos Space.
Risk Assessment:
High risks of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
Multiple cross-site scripting vulnerabilities exist in the Junos space software due to insufficient sanitization of user-supplied data. An attacker could exploit these vulnerabilities by sending specially crafted link and execute arbitrary HTML and script code in the affected users browser.
Successful exploitation of these vulnerabilities could allow the attacker to steal potentially sensitive information and change appearance of the web page.
Solution
Apply appropriate updates as mentioned in:
https://supportportal.juniper.net/s/article/2025-10-Security-Bulletin-Junos-Space-Multiple-XSS-vulnerabilities-resolved-in-24-1R4-release
Vendor Information
Juniper
https://supportportal.juniper.net/s/article/2025-10-Security-Bulletin-Junos-Space-Multiple-XSS-vulnerabilities-resolved-in-24-1R4-release
References
Juniper
https://supportportal.juniper.net/s/article/2025-10-Security-Bulletin-Junos-Space-Multiple-XSS-vulnerabilities-resolved-in-24-1R4-release
CVE Name
CVE-2025-59981
CVE-2025-59982
CVE-2025-59983
CVE-2025-59984
CVE-2025-59985
CVE-2025-59986
CVE-2025-59987
CVE-2025-59988
CVE-2025-59989
CVE-2025-59990
CVE-2025-59991
CVE-2025-59992
CVE-2025-59993
CVE-2025-59994
CVE-2025-59995
CVE-2025-59996
CVE-2025-59997
CVE-2025-59998
CVE-2025-59999
CVE-2025-60000
CVE-2025-60001
CVE-2025-60002
CVE-2025-60009
CVE-2025-59978
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjuXkMACgkQ3jCgcSdc
ys84Qw/9EtT7u8yRCZVvbNB99sM8nspcLeKB5Tug57mApmfZUAq9s9lvxrCXBnCN
hK0fH2iTut0dOMwwFVp8lNOftqyVMrJJDKLa9IXj/80/s/ZcaPc3RIS5RpzWPqcM
5KurRaryRzJI5X3aHKeB91UPw1DTx7etsI0FnwJSqiOzL686QljwSagomK25S0HH
uLBrfb466AaOc3QOLsIxunI8CeABQFwDX+58LN5crX/BUgqHsGb3eRtCMr3V+r2W
udeeMnnkZNNgrRXOWoTpobhO6niSiU2esIv8bdBNQV+lLNUKDPl5N2IDkoxSslXv
2alG98RlIit13wQkujpN3kxPw9ttxnEm1yTunk8t5WUmsXRy5ZFCoEDF5usRSxDK
54qHdA9zcNKRw6t7eMMdMKyCi7QNvzSriO2AxkVggftYuxYL0wmYOZJcwrRW9l7a
17sIWBnrw+au/DTKptW/B6/WjKUfGvLtPrHYtLcNHMzJnBI57bKOqH0pGCQcGIrd
o6wB3RG/VoFZ+ckNLarSLLPXVM4uC1Cjx83fM0X/9qwGrAkdvUHaCXjJRsaAOnlh
XY/txYMAn9rJKyU24Hj4UaU7KhkSl/wfP6QYsBq480Z2EV1ApFvDtmRjicrAOGJ8
6NOJNwodhnRcePX7nGbd8lx3FzgBmb8/ll0uoD8kJhR3PD2Nl6Y=
=GG0C
—–END PGP SIGNATURE—–