Back

MEDIUM

Junos Space: Authenticated user able to delete devices without delete device privileges

Published Jan 15, 2019

Description

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

Affected products

Remediation

Vendor solution

Use access lists or firewall filters to limit access to the device's management interface only from trusted hosts and administrators.

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Jan 15, 2019
Updated Sep 16, 2024
Reserved Oct 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner juniper
Published Jan 15, 2019
Updated Sep 16, 2024
Exploited since n/a
EUVD-2019-0823