Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-0248

Опубликовано: 22 апр. 2021
Источник: nvd
CVSS3: 10
CVSS2: 7.5
EPSS Низкий

Описание

This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This issue affects: Juniper Networks Junos OS versions prior to 19.1R1 on NFX Series. No other platforms besides NFX Series devices are affected.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
Версия до 19.1 (исключая)
cpe:2.3:o:juniper:junos:19.1:-:*:*:*:*:*:*

Одно из

cpe:2.3:h:juniper:nfx150:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:nfx250:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:nfx350:-:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.0042
Низкий

10 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-798
CWE-798

Связанные уязвимости

github
больше 3 лет назад

This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This issue affects: Juniper Networks Junos OS versions prior to 19.1R1 on NFX Series. No other platforms besides NFX Series devices are affected.

EPSS

Процентиль: 61%
0.0042
Низкий

10 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-798
CWE-798