Juniper Networks Junos Space vulnerabilities
49 known vulnerabilities affecting juniper_networks/junos_space.
Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM37
Vulnerabilities
Page 3 of 3
CVE-2017-10624HIGHCVSS 7.5vversions prior to 17.1R12017-10-13
CVE-2017-10624 [HIGH] CWE-345 CVE-2017-10624: Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-th
Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.
cvelistv5nvd
CVE-2017-10612HIGHCVSS 8.0vversions prior to 17.1R12017-10-13
CVE-2017-10612 [HIGH] CWE-79 CVE-2017-10612: A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can chang
A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.
cvelistv5nvd
CVE-2017-2306HIGHCVSS 8.8vversions prior to 16.1R12017-05-30
CVE-2017-2306 [HIGH] CWE-863 CVE-2017-2306: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
cvelistv5nvd
CVE-2017-2305HIGHCVSS 8.8vversions prior to 16.1R12017-05-30
CVE-2017-2305 [HIGH] CWE-863 CVE-2017-2305: On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
cvelistv5nvd
CVE-2017-2311MEDIUMCVSS 5.3vversions prior to 16.1R12017-05-30
CVE-2017-2311 [MEDIUM] CVE-2017-2311: On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with ne
On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.
cvelistv5nvd
CVE-2017-2307MEDIUMCVSS 6.1vversions prior to 16.1R12017-05-30
CVE-2017-2307 [MEDIUM] CWE-79 CVE-2017-2307: A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks J
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.
cvelistv5nvd
CVE-2017-2309MEDIUMCVSS 5.9vversions prior to 16.1R12017-05-30
CVE-2017-2309 [MEDIUM] CWE-200 CVE-2017-2309: On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is en
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
cvelistv5nvd
CVE-2017-2308MEDIUMCVSS 6.5vversions prior to 16.1R12017-05-30
CVE-2017-2308 [MEDIUM] CWE-611 CVE-2017-2308: An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
cvelistv5nvd
CVE-2017-2310MEDIUMCVSS 5.3vversions prior to 16.1R12017-05-30
CVE-2017-2310 [MEDIUM] CVE-2017-2310: A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
cvelistv5nvd
← Previous3 / 3