CVE-2018-0039
published 2018-07-11CVE-2018-0039: Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials…
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.97%
58.0th percentile
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | contrail | — | — |
| juniper | contrail_service_orchestration | < 4.0.0 | 4.0.0 |
| juniper_networks | contrail_service_orchestration | >= unspecified < 4.0.0 | 4.0.0 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2018-0039: Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These cred
vendor_juniper·2018-07-11·CVSS 6.5
CVE-2018-0039 [MEDIUM] CWE-561 CVE-2018-0039: Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These cred
CVE-2018-0039: Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.
GHSA
GHSA-v468-p66w-62gm: Juniper Networks Contrail Service Orchestration releases prior to 4
ghsa_unreviewed·2022-05-13
CVE-2018-0039 [CRITICAL] CWE-798 GHSA-v468-p66w-62gm: Juniper Networks Contrail Service Orchestration releases prior to 4
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-11
Published