CVE-2017-10616
published 2017-10-13CVE-2017-10616: The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.30%
67.3th percentile
The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | contrail | — | — |
| juniper | contrail | — | — |
| juniper | contrail | — | — |
| juniper | contrail | — | — |
| juniper | contrail | — | — |
| juniper | contrail | >= 2.2 < 2.21.4 | 2.21.4 |
| juniper | contrail | >= 3.0 < 3.0.3.4 | 3.0.3.4 |
| juniper | contrail | >= 3.1 < 3.1.4.0 | 3.1.4.0 |
| juniper | contrail | >= 3.2 < 3.2.5.0 | 3.2.5.0 |
| juniper_networks | contrail | >= 2.2 < 2.21.4 | 2.21.4 |
| juniper_networks | contrail | >= 3.0 < 3.0.3.4 | 3.0.3.4 |
| juniper_networks | contrail | >= 3.1 < 3.1.4.0 | 3.1.4.0 |
| juniper_networks | contrail | >= 3.2 < 3.2.5.0 | 3.2.5.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2017-10617: The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sys
vendor_juniper·2017-10-13·CVSS 5.0
CVE-2017-10617 [MEDIUM] CWE-611 CVE-2017-10617: The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sys
CVE-2017-10617: The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
Juniper
CVE-2017-10616: The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2
vendor_juniper·2017-10-13·CVSS 5.3
CVE-2017-10616 [MEDIUM] CWE-798 CVE-2017-10616: The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2
CVE-2017-10616: The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
GHSA
GHSA-f3v5-rq6c-674f: The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sys
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2017-10617 [MEDIUM] CWE-611 GHSA-f3v5-rq6c-674f: The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sys
The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
GHSA
GHSA-hhp8-q7c4-jx53: The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2017-10616 [MEDIUM] CWE-798 GHSA-hhp8-q7c4-jx53: The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials
The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-13
Published