Junos Space: Authenticated user able to delete devices without delete device privileges
Published Jan 15, 2019
6.5
MEDIUMCVSS 3.0
EPSS 0.93%
Description
A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<18.3R1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos Space | n/a |
|
- 13.3
- 13.3
- 13.3
- 13.3
- 14.1
- 14.1
- 14.1
- 14.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.2
- 15.2
- 15.2
- 16.1
- 16.1
- 16.1
- 16.1
- 17.1
- 17.2
- 18.1
- 18.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Use access lists or firewall filters to limit access to the device's management interface only from trusted hosts and administrators.
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0823 Advisory
- https://kb.juniper.net/JSA10917 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0823 | Advisory | |
| https://kb.juniper.net/JSA10917 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.