PT-2014-2003 · Juniper Networks+1 · Junos Space+1
Published
2014-05-14
·
Updated
2018-08-10
·
CVE-2014-3413
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos Space versions prior to 13.3R1.8
Description
The issue is related to the use of predefined credentials in the MySQL server of the Juniper Networks Junos Space platform. This allows a remote attacker to gain access with administrative privileges by exploiting the hardcoded password of an unspecified account, potentially leading to the obtainment of sensitive information and administrative control through database access.
Recommendations
For versions prior to 13.3R1.8, update to version 13.3R1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the MySQL server to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Space
Mysql Server