CVE-2017-2321
published 2017-04-24CVE-2017-2321: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged…
PriorityP344high8.6CVSS 3.0
AVNACLPRNUINSUCLILAH
EPSS
1.45%
70.4th percentile
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | northstar_controller | <= 2.1.0 | — |
| juniper_networks | northstar_controller_application | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6phr-4r76-8mwj: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2
ghsa_unreviewed·2022-05-13
CVE-2017-2321 [HIGH] GHSA-6phr-4r76-8mwj: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.
Juniper
CVE-2017-2321: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged,
vendor_juniper·2017-04-24·CVSS 8.6
CVE-2017-2321 [HIGH] CVE-2017-2321: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged,
CVE-2017-2321: A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.
No detection rules found.
Nuclei
ZTE Cable Modem Web Shell
nuclei·CVSS 10.0
CVE-2014-2321 [CRITICAL] ZTE Cable Modem Web Shell
ZTE Cable Modem Web Shell
ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests to web_shell_cmd.gch, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.
Template:
id: CVE-2014-2321
info:
name: ZTE Cable Modem Web Shell
author: geeknik
severity: critical
description: |
ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests to web_shell_cmd.gch, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.
impact: |
Remote code execution
remediation: |
Apply the latest firmware update provided by ZTE to fix the vulnerability
reference:
- https://yosmelvin.wordpress.com/2017/09/21/f660-mo
No writeups or analysis indexed.
2017-04-24
Published