PT-2017-7952 · Juniper Networks · Junos Space

Published

2017-10-13

·

Updated

2019-10-09

·

CVE-2016-1265

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos Space versions prior to 15.1R3
Description A remote unauthenticated network-based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross-site request forgery (CSRF), default authentication credentials, information leak, and command injection attack vectors.
Recommendations For versions prior to 15.1R3, update to version 15.1R3 or later to resolve the issue. As a temporary workaround, consider restricting access to Junos Space and changing default authentication credentials to minimize the risk of exploitation. Avoid using vulnerable API endpoints until the issue is resolved.

Fix

CSRF

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1265

Affected Products

Junos Space