Lucene search

K
cve[email protected]CVE-2013-6012
HistoryOct 28, 2013 - 10:55 p.m.

CVE-2013-6012

2013-10-2822:55:04
CWE-287
web.nvd.nist.gov
17
juniper
junos
cve-2013-6012
security
configuration validation
authentication
remote attackers
nvd

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.2%

Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows remote attackers to bypass authentication via unspecified vectors.

Affected configurations

NVD
Node
juniperjunosMatch12.1x44
OR
juniperjunosMatch12.1x45

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.2%

Related for CVE-2013-6012