Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-0265

Опубликовано: 22 апр. 2021
Источник: nvd
CVSS3: 8.1
CVSS2: 10
EPSS Низкий

Описание

An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on the host running the AppFormix Agent, when certain preconditions are performed by the attacker, thus granting the attacker full control over the environment. This issue affects: Juniper Networks AppFormix 3 versions prior to 3.1.22, 3.2.14, 3.3.0.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:juniper:appformix:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.1.22 (исключая)
cpe:2.3:a:juniper:appformix:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.14 (исключая)

EPSS

Процентиль: 90%
0.05431
Низкий

8.1 High

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

github
больше 3 лет назад

An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on the host running the AppFormix Agent, when certain preconditions are performed by the attacker, thus granting the attacker full control over the environment. This issue affects: Juniper Networks AppFormix 3 versions prior to 3.1.22, 3.2.14, 3.3.0.

EPSS

Процентиль: 90%
0.05431
Низкий

8.1 High

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78