HIGH
Junos Space: Unrestricted file upload vulnerability
Published Jan 15, 2019
8.8
HIGHCVSS 3.0
EPSS 1.10%
Description
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<18.3R1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos Space | n/a |
|
OR
- 13.3
- 13.3
- 13.3
- 13.3
- 14.1
- 14.1
- 14.1
- 14.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.2
- 15.2
- 15.2
- 16.1
- 16.1
- 16.1
- 16.1
- 17.1
- 17.2
- 18.1
- 18.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Use access lists or firewall filters to limit access to the device's management interface only from trusted hosts and administrators.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0824 Advisory
- https://kb.juniper.net/JSA10917 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0824 | Advisory | |
| https://kb.juniper.net/JSA10917 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Jan 15, 2019
Updated Sep 16, 2024
Reserved Oct 11, 2018
Link CVE-2019-0017
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0824 Assigner juniper
Published Jan 15, 2019
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2019-0824