CVE-2018-0023 — Incorrect Default Permissions in Networks Junos Snapshot Administrator
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateDec 18
Description
JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. The default configuration and sample files of JSNAPy automation tool versions prior to 1.3.0 are created world writable. This insecure file and directory permission allows unprivileged local users to alter the files under this directory including inserting operations not intended by the package maintainer, system administrator, or other users. This issue only affects users who d…
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
3OSV▶
CVE-2018-0023: JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github↗2018-04-11
💥Exploits & PoCs
5Exploit-DB
▶
📋Vendor Advisories
1Juniper▶
CVE-2018-0023: JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. The default configuration and s↗2018-04-11