CVE-2017-2320
published 2017-04-24CVE-2017-2320: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged…
PriorityP356critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
1.86%
76.7th percentile
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | northstar_controller | <= 2.1.0 | — |
| juniper_networks | northstar_controller_application | — | — |
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jw9m-g475-84fv: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2
ghsa_unreviewed·2022-05-13
CVE-2017-2320 [CRITICAL] CWE-200 GHSA-jw9m-g475-84fv: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.
Juniper
CVE-2017-2320: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged,
vendor_juniper·2017-04-24·CVSS 10.0
CVE-2017-2320 [CRITICAL] CWE-200 CVE-2017-2320: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged,
CVE-2017-2320: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-04-24
Published