Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r2w-j4p7-rw4p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1.

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1.

EPSS

Процентиль: 73%
0.00752
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость маршрутизатора Juniper Networks 128 Technology Session Smart Router, связанная с обходом аутентификации, позволяющая нарушителю просматривать внутренние файлы, изменять настройки, манипулировать службами и выполнить произвольный код

EPSS

Процентиль: 73%
0.00752
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287