PT-2014-2003 · Juniper Networks+1 · Junos Space+1

Publicado

2014-05-14

·

Atualizado

2018-08-10

·

CVE-2014-3413

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos Space versions prior to 13.3R1.8
Description The issue is related to the use of predefined credentials in the MySQL server of the Juniper Networks Junos Space platform. This allows a remote attacker to gain access with administrative privileges by exploiting the hardcoded password of an unspecified account, potentially leading to the obtainment of sensitive information and administrative control through database access.
Recommendations For versions prior to 13.3R1.8, update to version 13.3R1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the MySQL server to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00794
CVE-2014-3413

Produtos afetados

Junos Space
Mysql Server