Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r2p-hq88-fpcf

Опубликовано: 11 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.

Due to a wrong initialization, specific processes which should only be able to communicate internally within the device can be reached over the network via open ports.

This issue affects Junos OS Evolved on ACX 7000 Series:

  • All versions before 21.4R3-S7-EVO,
  • 22.2-EVO

versions

before 22.2R3-S4-EVO,

  • 22.3-EVO versions before 22.3R3-S3-EVO,
  • 22.4-EVO versions before 22.4R3-S2-EVO,
  • 23.2-EVO versions before 23.2R2-EVO,
  • 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO.

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.

Due to a wrong initialization, specific processes which should only be able to communicate internally within the device can be reached over the network via open ports.

This issue affects Junos OS Evolved on ACX 7000 Series:

  • All versions before 21.4R3-S7-EVO,
  • 22.2-EVO

versions

before 22.2R3-S4-EVO,

  • 22.3-EVO versions before 22.3R3-S3-EVO,
  • 22.4-EVO versions before 22.4R3-S2-EVO,
  • 23.2-EVO versions before 23.2R2-EVO,
  • 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO.

EPSS

Процентиль: 49%
0.00257
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-923

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, specific processes which should only be able to communicate internally within the device can be reached over the network via open ports. This issue affects Junos OS Evolved on ACX 7000 Series: * All versions before 21.4R3-S7-EVO, * 22.2-EVO versions before 22.2R3-S4-EVO, * 22.3-EVO versions before 22.3R3-S3-EVO, * 22.4-EVO versions before 22.4R3-S2-EVO, * 23.2-EVO versions before 23.2R2-EVO, * 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость операционной системы Juniper Networks Junos OS Evolved, связанная с недостаточным ограничением канала связи для заданных конечных точек, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и вызвать отказ в обслуживании

EPSS

Процентиль: 49%
0.00257
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-923