PT-2017-7952 · Juniper Networks · Junos Space
Published
2017-10-13
·
Updated
2019-10-09
·
CVE-2016-1265
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos Space versions prior to 15.1R3
Description
A remote unauthenticated network-based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross-site request forgery (CSRF), default authentication credentials, information leak, and command injection attack vectors.
Recommendations
For versions prior to 15.1R3, update to version 15.1R3 or later to resolve the issue. As a temporary workaround, consider restricting access to Junos Space and changing default authentication credentials to minimize the risk of exploitation. Avoid using vulnerable API endpoints until the issue is resolved.
Fix
CSRF
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos Space