Juniper Junos Space vulnerabilities
77 known vulnerabilities affecting juniper/junos_space.
Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH16MEDIUM51
Vulnerabilities
Page 3 of 4
CVE-2017-10623HIGHCVSS 8.1≤ 16.22017-10-13
CVE-2017-10623 [HIGH] CWE-287 CVE-2017-10623: Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may all
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.
nvd
CVE-2017-10624HIGHCVSS 7.5≤ 16.12017-10-13
CVE-2017-10624 [HIGH] CWE-345 CVE-2017-10624: Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-th
Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.
nvd
CVE-2017-10612HIGHCVSS 8.0≤ 16.1r32017-10-13
CVE-2017-10612 [HIGH] CWE-79 CVE-2017-10612: A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can chang
A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.
nvd
CVE-2017-2305HIGHCVSS 8.8≤ 16.12017-05-30
CVE-2017-2305 [HIGH] CWE-863 CVE-2017-2305: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
nvd
CVE-2017-2306HIGHCVSS 8.8≤ 16.12017-05-30
CVE-2017-2306 [HIGH] CWE-863 CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
nvd
CVE-2017-2311MEDIUMCVSS 5.3≤ 16.12017-05-30
CVE-2017-2311 [MEDIUM] CVE-2017-2311: On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with ne
On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.
nvd
CVE-2017-2308MEDIUMCVSS 6.5≤ 16.12017-05-30
CVE-2017-2308 [MEDIUM] CWE-611 CVE-2017-2308: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
nvd
CVE-2017-2310MEDIUMCVSS 5.3≤ 15.22017-05-30
CVE-2017-2310 [MEDIUM] CVE-2017-2310: A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
nvd
CVE-2017-2309MEDIUMCVSS 5.9≤ 16.12017-05-30
CVE-2017-2309 [MEDIUM] CWE-200 CVE-2017-2309: On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is en
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
nvd
CVE-2017-2307MEDIUMCVSS 6.1≤ 15.22017-05-30
CVE-2017-2307 [MEDIUM] CWE-79 CVE-2017-2307: A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks J
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.
nvd
CVE-2016-4926CRITICALCVSS 9.8≤ 15.22017-03-20
CVE-2016-4926 [CRITICAL] CWE-287 CVE-2016-4926: Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based u
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.
nvd
CVE-2016-4927HIGHCVSS 8.1≤ 15.22017-03-20
CVE-2016-4927 [HIGH] CWE-20 CVE-2016-4927: Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) typ
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
nvd
CVE-2016-4929HIGHCVSS 8.8≤ 15.22017-03-20
CVE-2016-4929 [HIGH] CWE-77 CVE-2016-4929: Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary c
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
nvd
CVE-2016-4928HIGHCVSS 8.8≤ 15.22017-03-20
CVE-2016-4928 [HIGH] CWE-352 CVE-2016-4928: Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to per
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
nvd
CVE-2016-4931MEDIUMCVSS 6.5≤ 15.22017-03-20
CVE-2016-4931 [MEDIUM] CWE-611 CVE-2016-4931: XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
nvd
CVE-2016-4930MEDIUMCVSS 6.1≤ 15.22017-03-20
CVE-2016-4930 [MEDIUM] CWE-79 CVE-2016-4930: Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to ste
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
nvd
CVE-2015-2620MEDIUMCVSS 4.3≤ 15.12015-07-16
CVE-2015-2620 [MEDIUM] CVE-2015-2620: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2015-3209HIGHCVSS 7.5≤ 15.12015-06-15
CVE-2015-3209 [HIGH] CWE-787 CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitr
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
nvd
CVE-2015-0501MEDIUMCVSS 5.7≤ 15.12015-04-16
CVE-2015-0501 [MEDIUM] CVE-2015-0501: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
nvd
CVE-2014-6500HIGHCVSS 7.5≤ 15.12014-10-15
CVE-2014-6500 [HIGH] CVE-2014-6500: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.
nvd