Lucene search

K
cveJuniperCVE-2019-0017
HistoryJan 15, 2019 - 9:29 p.m.

CVE-2019-0017

2019-01-1521:29:01
CWE-434
juniper
web.nvd.nist.gov
41
junos space
juniper networks
security vulnerability
cve-2019-0017
nvd
malicious image upload
insufficient validity checking

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

42.8%

The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

Affected configurations

Nvd
Node
juniperjunos_spaceMatch13.3r1
OR
juniperjunos_spaceMatch13.3r2
OR
juniperjunos_spaceMatch13.3r3
OR
juniperjunos_spaceMatch13.3r4
OR
juniperjunos_spaceMatch14.1-
OR
juniperjunos_spaceMatch14.1r1
OR
juniperjunos_spaceMatch14.1r2
OR
juniperjunos_spaceMatch14.1r3
OR
juniperjunos_spaceMatch15.1r1
OR
juniperjunos_spaceMatch15.1r2
OR
juniperjunos_spaceMatch15.1r3
OR
juniperjunos_spaceMatch15.1r4
OR
juniperjunos_spaceMatch15.2-
OR
juniperjunos_spaceMatch15.2r1
OR
juniperjunos_spaceMatch15.2r2
OR
juniperjunos_spaceMatch16.1-
OR
juniperjunos_spaceMatch16.1r1
OR
juniperjunos_spaceMatch16.1r2
OR
juniperjunos_spaceMatch16.1r3
OR
juniperjunos_spaceMatch17.1r1
OR
juniperjunos_spaceMatch17.2r1.4
OR
juniperjunos_spaceMatch18.1r1
OR
juniperjunos_spaceMatch18.2r1
VendorProductVersionCPE
juniperjunos_space13.3cpe:2.3:a:juniper:junos_space:13.3:r1:*:*:*:*:*:*
juniperjunos_space13.3cpe:2.3:a:juniper:junos_space:13.3:r2:*:*:*:*:*:*
juniperjunos_space13.3cpe:2.3:a:juniper:junos_space:13.3:r3:*:*:*:*:*:*
juniperjunos_space13.3cpe:2.3:a:juniper:junos_space:13.3:r4:*:*:*:*:*:*
juniperjunos_space14.1cpe:2.3:a:juniper:junos_space:14.1:-:*:*:*:*:*:*
juniperjunos_space14.1cpe:2.3:a:juniper:junos_space:14.1:r1:*:*:*:*:*:*
juniperjunos_space14.1cpe:2.3:a:juniper:junos_space:14.1:r2:*:*:*:*:*:*
juniperjunos_space14.1cpe:2.3:a:juniper:junos_space:14.1:r3:*:*:*:*:*:*
juniperjunos_space15.1cpe:2.3:a:juniper:junos_space:15.1:r1:*:*:*:*:*:*
juniperjunos_space15.1cpe:2.3:a:juniper:junos_space:15.1:r2:*:*:*:*:*:*
Rows per page:
1-10 of 231

CNA Affected

[
  {
    "product": "Junos Space",
    "vendor": "Juniper Networks",
    "versions": [
      {
        "lessThan": "18.3R1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVE-2019-0017