cbcvebase.
CVE-2016-1265
published 2017-10-13

CVE-2016-1265: A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos…

PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.30%
81.3th percentile
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.

Affected

4 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniperjunos_space<= 15.1r2
juniperjunos_space
juniper_networksjunos_os

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vectors include cross-site request forgery (CSRF), default authentication credentials, information leak, and command injection against Junos Space
  • All Juniper Networks Junos Space versions prior to 15.1R3 are vulnerable; detect or alert on use of these versions in the environment
  • ·Default authentication credentials are an explicit attack vector; ensure Junos Space is not deployed with factory/default credentials

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.