9.8

CVE-2017-10615

A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to potentially execute arbitrary code or crash daemons such as telnetd or sshd that make use of PAM. Affected Juniper Networks Junos OS releases are: 14.1 from 14.1R5 prior to 14.1R8-S4, 14.1R9; 14.1X53 prior to 14.1X53-D50 on EX and QFX series; 14.2 from 14.2R3 prior to 14.2R7-S8, 14.2R8; No other Junos OS releases are affected by this issue. No other Juniper Networks products are affected by this issue.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Version14.1
JuniperJunos Version14.1 Updater1
JuniperJunos Version14.1 Updater2
JuniperJunos Version14.1 Updater3
JuniperJunos Version14.1 Updater4
JuniperJunos Version14.1 Updater5
JuniperJunos Version14.1 Updater6
JuniperJunos Version14.1 Updater7
JuniperJunos Version14.1 Updater9
JuniperJunos Version14.1x53
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated10
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated15
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated16
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated25
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated26
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated27
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated30
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated35
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated40
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.1x53 Updated45
   JuniperEx3200 Version-
   JuniperEx3300 Version-
   JuniperEx3300-vc Version-
   JuniperEx4200 Version-
   JuniperEx4200-vc Version-
   JuniperEx4300 Version-
   JuniperEx4300-vc Version-
   JuniperEx4500 Version-
   JuniperEx4500-vc Version-
   JuniperEx4550 Version-
   JuniperEx4550-vc Version-
   JuniperEx4600 Version-
   JuniperEx4600-vc Version-
   JuniperEx6200 Version-
   JuniperEx8200 Version-
   JuniperEx8200-vc Version-
JuniperJunos Version14.2
JuniperJunos Version14.2 Updater1
JuniperJunos Version14.2 Updater2
JuniperJunos Version14.2 Updater3
JuniperJunos Version14.2 Updater4
JuniperJunos Version14.2 Updater5
JuniperJunos Version14.2 Updater6
JuniperJunos Version14.2 Updater7
JuniperJunos Version14.2 Updater8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.72% 0.813
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
sirt@juniper.net 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.