CVE-2019-0047 describes a persistent Cross-Site Scripting (XSS) vulnerability in the J-Web interface of Juniper Networks Junos OS, affecting numerous versions across multiple releases. This flaw allows remote unauthenticated attackers to potentially execute administrative actions on the device, but only after a Junos administrator performs specific diagnostic actions within J-Web. The vulnerability carries a high CVSS score of 8.8, indicating a significant risk. Its attack vector is network-based, with low attack complexity, but requires user interaction (UI:R) from an administrator. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a low level of public awareness or active threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1X46, < 12.1X46-D86CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 12.3, < 12.3R12-S13CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 12.3X48, < 12.3X48-D80CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 14.1X53, < 14.1X53-D51CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 16.1, < 16.1R7-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.