CVE-2013-5097
published 2013-08-16CVE-2013-5097: Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.34%
68.4th percentile
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos_os | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
| juniper | junos_space | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2013-5097: Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user acco
vendor_juniper·2013-08-16·CVSS 4.0
CVE-2013-5097 [MEDIUM] CWE-264 CVE-2013-5097: Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user acco
CVE-2013-5097: Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
GHSA
GHSA-3g92-xpx3-5xx5: Juniper Junos Space before 13
ghsa_unreviewed·2022-05-17
CVE-2013-5097 [MEDIUM] GHSA-3g92-xpx3-5xx5: Juniper Junos Space before 13
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-08-16
Published