CVE-2025-59968 (CNNVD-202510-1330)
中文标题:
Juniper Networks Junos Space Security Director 安全漏洞
英文标题:
Junos Space Security Director: Insufficient authorization for sensitive resources in web interface
漏洞描述
中文描述:
Juniper Networks Junos Space Security Director是美国瞻博网络(Juniper Networks)公司的一款用于管理Junos Space解决方案的应用程序。 Juniper Networks Junos Space Security Director 24.1R3 Patch V4之前版本存在安全漏洞,该漏洞源于缺少授权,可能导致未经身份验证的攻击者通过Web界面读取或修改元数据,进而绕过安全控制。
英文描述:
A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface. Tampering with this metadata can result in managed SRX Series devices permitting network traffic that should otherwise be blocked by policy, effectively bypassing intended security controls. This issue affects Junos Space Security Director * all versions prior to 24.1R3 Patch V4 This issue does not affect managed cSRX Series devices.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Juniper Networks | Junos Space Security Director | - | < 24.1R3 Patch V4 | - |
cpe:2.3:a:juniper_networks:junos_space_security_director:*:*:*:*:*:*:*:*
|
| Juniper Networks | Junos OS | - | - | - |
cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
|
| Juniper Networks | Junos OS | 0 | - | - |
cpe:2.3:a:juniper_networks:junos_os:0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/AU:Y/R:A/V:C/RE:M/U:Green
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-59968 |
2025-11-11 15:23:31 | 2025-11-11 07:40:47 |
| NVD | nvd_CVE-2025-59968 |
2025-11-11 15:01:05 | 2025-11-11 07:48:34 |
| CNNVD | cnnvd_CNNVD-202510-1330 |
2025-11-11 15:12:27 | 2025-11-11 08:00:16 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202510-1330
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']