CVE-2017-2309Sensitive Information Exposure in Juniper Junos Space

Severity
5.9MEDIUMNVD
EPSS
0.2%
top 55.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateMay 17

Description

On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5juniper_networks/junos_spaceversions prior to 16.1R1

🔴Vulnerability Details

2
GHSA
GHSA-x7wv-hq5r-rg59: On Juniper Networks Junos Space versions prior to 162022-05-17
CVEList
CVE-2017-2309: On Juniper Networks Junos Space versions prior to 162017-05-30

📋Vendor Advisories

1
Juniper
CVE-2017-2309: On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted2017-05-30
CVE-2017-2309 — Sensitive Information Exposure | cvebase