Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-52987

Опубликовано: 15 янв. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control. 

This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:juniper:paragon_automation:*:*:*:*:*:*:*:*
Версия до 24.1.1 (исключая)

EPSS

Процентиль: 8%
0.00031
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.1
github
23 дня назад

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control.  This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.

EPSS

Процентиль: 8%
0.00031
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021