CVE-2018-0059 is a persistent cross-site scripting (XSS) vulnerability affecting the graphical user interface of Juniper Networks ScreenOS versions prior to 6.3.0r26. An authenticated attacker could inject malicious web script or HTML, potentially stealing sensitive data and credentials from an administrative web session or tricking an administrator into performing unauthorized actions. This vulnerability has a CVSS score of 5.4 (Medium), indicating a low attack complexity and requiring user interaction, but with the potential for low impact on confidentiality and integrity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.3.0CPE matchmatch criteria | cpe:2.3:o:juniper:netscreen_screenos:6.3.0:*:*:*:*:*:*:* | ||
6.3.0r1CPE matchmatch criteria | cpe:2.3:o:juniper:netscreen_screenos:6.3.0r1:*:*:*:*:*:*:* | ||
6.3.0r2CPE matchmatch criteria | cpe:2.3:o:juniper:netscreen_screenos:6.3.0r2:*:*:*:*:*:*:* | ||
6.3.0r3CPE matchmatch criteria | cpe:2.3:o:juniper:netscreen_screenos:6.3.0r3:*:*:*:*:*:*:* | ||
6.3.0r4CPE matchmatch criteria | cpe:2.3:o:juniper:netscreen_screenos:6.3.0r4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.