Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31352

Опубликовано: 19 окт. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers, which could allow a remote attacker to obtain sensitive information. A remote attacker with read and write access to network data could exploit this vulnerability to display plaintext bits from a block of ciphertext and obtain sensitive information. This issue affects all Juniper Networks SRC Series versions prior to 4.13.0-R6.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:juniper:session_and_resource_control:*:*:*:*:*:*:*:*
Версия до 4.130r6 (исключая)

EPSS

Процентиль: 32%
0.00122
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-327

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers, which could allow a remote attacker to obtain sensitive information. A remote attacker with read and write access to network data could exploit this vulnerability to display plaintext bits from a block of ciphertext and obtain sensitive information. This issue affects all Juniper Networks SRC Series versions prior to 4.13.0-R6.

EPSS

Процентиль: 32%
0.00122
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-327