CVE-2017-2306
published 2017-05-30CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web…
PriorityP350high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.59%
72.9th percentile
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos_os | — | — |
| juniper | junos_space | <= 16.1 | — |
| juniper | junos_space | — | — |
| juniper_networks | junos_space | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative
vendor_juniper·2017-05-30·CVSS 8.8
CVE-2017-2306 [HIGH] CWE-863 CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative
CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
GHSA
GHSA-jffw-8f4h-x7fq: On Juniper Networks Junos Space versions prior to 16
ghsa_unreviewed·2022-05-13
CVE-2017-2306 [HIGH] CWE-863 GHSA-jffw-8f4h-x7fq: On Juniper Networks Junos Space versions prior to 16
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-05-30
Published