PT-2017-3100 · Juniper Networks · Northstar Controller Application

Publicado

2017-04-12

·

Atualizado

2019-10-03

·

CVE-2017-2320

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks NorthStar Controller Application versions prior to 2.1.0 Service Pack 1
Description The issue is related to inadequate access control in the NorthStar Controller Application, which may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of service. This could lead to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management. The attacker could exploit this issue to disrupt services or gain access to sensitive information.
Recommendations For versions prior to 2.1.0 Service Pack 1, update to version 2.1.0 Service Pack 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the NorthStar Controller Application to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02480
CVE-2017-2320

Produtos afetados

Northstar Controller Application