ID

VAR-201705-3371


CVE

CVE-2017-2307


TITLE

Juniper Networks Junos Space Cross-Site Scripting Vulnerability in Microsoft Management Interface

Trust: 0.8

sources: JVNDB: JVNDB-2017-004484

DESCRIPTION

A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space. Juniper Junos Space is prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Versions prior to Juniper Junos Space 16.1R1 are vulnerable. Juniper Networks Junos Space is a set of network management solutions of Juniper Networks (Juniper Networks). The solution supports automated configuration, monitoring, and troubleshooting of devices and services throughout their lifecycle

Trust: 1.98

sources: NVD: CVE-2017-2307 // JVNDB: JVNDB-2017-004484 // BID: 98749 // VULHUB: VHN-110510

AFFECTED PRODUCTS

vendor:junipermodel:junos spacescope:lteversion:15.2

Trust: 1.0

vendor:junipermodel:junos spacescope:eqversion:15.2

Trust: 0.9

vendor:junipermodel:junos spacescope:ltversion:16.1r1

Trust: 0.8

vendor:junipermodel:junos spacescope:eqversion:1.2.2

Trust: 0.3

vendor:junipermodel:junos space 15.2r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.2r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.1r3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.1r2.11scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.1r2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.1r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.1f3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 15.1f2scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 14.1r1.9scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 14.1r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 14.1.r3.4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 13.3r4.4scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 13.3r1.9scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 13.3r1.8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:13.3

Trust: 0.3

vendor:junipermodel:junos space 13.1r1.6scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 13.1r1scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 13.1p1.14scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space r1.8scope:eqversion:13.1

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:13.1

Trust: 0.3

vendor:junipermodel:junos space 12.3r2.8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 12.3r1.3scope: - version: -

Trust: 0.3

vendor:junipermodel:junos space 12.3p2.8scope: - version: -

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:12.3

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:12.2

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:12.1

Trust: 0.3

vendor:junipermodel:junos space 11.4r5.5scope: - version: -

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:11.4

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:11.3

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:11.2

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:11.1

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:1.4

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:1.3

Trust: 0.3

vendor:junipermodel:junos spacescope:eqversion:1.0

Trust: 0.3

vendor:junipermodel:junos space 16.1r1scope:neversion: -

Trust: 0.3

sources: BID: 98749 // JVNDB: JVNDB-2017-004484 // CNNVD: CNNVD-201705-1352 // NVD: CVE-2017-2307

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-2307
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-2307
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201705-1352
value: MEDIUM

Trust: 0.6

VULHUB: VHN-110510
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-2307
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-110510
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-2307
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-110510 // JVNDB: JVNDB-2017-004484 // CNNVD: CNNVD-201705-1352 // NVD: CVE-2017-2307

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-110510 // JVNDB: JVNDB-2017-004484 // NVD: CVE-2017-2307

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201705-1352

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201705-1352

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-004484

PATCH

title:JSA10770url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10770&actp=METADATA

Trust: 0.8

title:Juniper Networks Junos Space Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=70626

Trust: 0.6

sources: JVNDB: JVNDB-2017-004484 // CNNVD: CNNVD-201705-1352

EXTERNAL IDS

db:NVDid:CVE-2017-2307

Trust: 2.8

db:JUNIPERid:JSA10770

Trust: 2.0

db:BIDid:98749

Trust: 1.4

db:JVNDBid:JVNDB-2017-004484

Trust: 0.8

db:CNNVDid:CNNVD-201705-1352

Trust: 0.7

db:NSFOCUSid:36769

Trust: 0.6

db:VULHUBid:VHN-110510

Trust: 0.1

sources: VULHUB: VHN-110510 // BID: 98749 // JVNDB: JVNDB-2017-004484 // CNNVD: CNNVD-201705-1352 // NVD: CVE-2017-2307

REFERENCES

url:https://kb.juniper.net/jsa10770

Trust: 1.7

url:http://www.securityfocus.com/bid/98749

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-2307

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-2307

Trust: 0.8

url:http://www.nsfocus.net/vulndb/36769

Trust: 0.6

url:http://www.juniper.net/

Trust: 0.3

url:http://www.juniper.net/au/en/products-services/software/junos-platform/junos-space/

Trust: 0.3

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10770&actp=rss

Trust: 0.3

sources: VULHUB: VHN-110510 // BID: 98749 // JVNDB: JVNDB-2017-004484 // CNNVD: CNNVD-201705-1352 // NVD: CVE-2017-2307

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 98749

SOURCES

db:VULHUBid:VHN-110510
db:BIDid:98749
db:JVNDBid:JVNDB-2017-004484
db:CNNVDid:CNNVD-201705-1352
db:NVDid:CVE-2017-2307

LAST UPDATE DATE

2024-11-23T21:04:27.149000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-110510date:2017-06-08T00:00:00
db:BIDid:98749date:2017-05-30T00:00:00
db:JVNDBid:JVNDB-2017-004484date:2017-06-27T00:00:00
db:CNNVDid:CNNVD-201705-1352date:2017-05-31T00:00:00
db:NVDid:CVE-2017-2307date:2024-11-21T03:23:15.180

SOURCES RELEASE DATE

db:VULHUBid:VHN-110510date:2017-05-30T00:00:00
db:BIDid:98749date:2017-05-30T00:00:00
db:JVNDBid:JVNDB-2017-004484date:2017-06-27T00:00:00
db:CNNVDid:CNNVD-201705-1352date:2017-05-31T00:00:00
db:NVDid:CVE-2017-2307date:2017-05-30T14:29:00.957