Lucene search

K
cve[email protected]CVE-2013-4689
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-4689

2022-10-0316:14:58
CWE-352
web.nvd.nist.gov
21
cve-2013-4689
j-web
juniper junos
csrf protection
remote attackers

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.9%

J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.

Affected configurations

NVD
Node
juniperjunosRange10.4
OR
juniperjunosMatch4.0
OR
juniperjunosMatch4.1
OR
juniperjunosMatch4.2
OR
juniperjunosMatch4.3
OR
juniperjunosMatch4.4
OR
juniperjunosMatch5.0
OR
juniperjunosMatch5.1
OR
juniperjunosMatch5.2
OR
juniperjunosMatch5.3
OR
juniperjunosMatch5.4
OR
juniperjunosMatch5.5
OR
juniperjunosMatch5.6
OR
juniperjunosMatch5.7
OR
juniperjunosMatch6.0
OR
juniperjunosMatch6.1
OR
juniperjunosMatch6.2
OR
juniperjunosMatch6.3
OR
juniperjunosMatch6.4
OR
juniperjunosMatch7.0
OR
juniperjunosMatch7.1
OR
juniperjunosMatch7.2
OR
juniperjunosMatch7.3
OR
juniperjunosMatch7.4
OR
juniperjunosMatch7.5
OR
juniperjunosMatch7.6
OR
juniperjunosMatch8.0
OR
juniperjunosMatch8.1
OR
juniperjunosMatch8.2
OR
juniperjunosMatch8.3
OR
juniperjunosMatch8.4
OR
juniperjunosMatch9.0
OR
juniperjunosMatch9.1
OR
juniperjunosMatch9.2
OR
juniperjunosMatch9.4
OR
juniperjunosMatch9.5
OR
juniperjunosMatch9.6
OR
juniperjunosMatch11.4
OR
juniperjunosMatch12.1
OR
juniperjunosMatch12.1x44
OR
juniperjunosMatch12.1x45
OR
juniperjunosMatch12.2
OR
juniperjunosMatch12.3
OR
juniperjunosMatch13.1

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.9%

Related for CVE-2013-4689