CVE-2017-2308
published 2017-05-30CVE-2017-2308: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files…
PriorityP338medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.21%
65.0th percentile
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos_os | — | — |
| juniper | junos_space | <= 16.1 | — |
| juniper | junos_space | — | — |
| juniper_networks | junos_space | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2017-2308: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitr
vendor_juniper·2017-05-30·CVSS 6.5
CVE-2017-2308 [MEDIUM] CWE-611 CVE-2017-2308: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitr
CVE-2017-2308: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
GHSA
GHSA-8288-c5xc-3655: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16
ghsa_unreviewed·2022-05-17
CVE-2017-2308 [MEDIUM] CWE-611 GHSA-8288-c5xc-3655: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-05-30
Published