PT-2014-2003 · Juniper Networks+1 · Junos Space+1
Publicado
2014-05-14
·
Atualizado
2018-08-10
·
CVE-2014-3413
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos Space versions prior to 13.3R1.8
Description
The issue is related to the use of predefined credentials in the MySQL server of the Juniper Networks Junos Space platform. This allows a remote attacker to gain access with administrative privileges by exploiting the hardcoded password of an unspecified account, potentially leading to the obtainment of sensitive information and administrative control through database access.
Recommendations
For versions prior to 13.3R1.8, update to version 13.3R1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the MySQL server to minimize the risk of exploitation.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Junos Space
Mysql Server