6.5

CVE-2018-0014

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperScreenos Version6.3.0r1
JuniperScreenos Version6.3.0r2
JuniperScreenos Version6.3.0r3
JuniperScreenos Version6.3.0r4
JuniperScreenos Version6.3.0r5
JuniperScreenos Version6.3.0r6
JuniperScreenos Version6.3.0r7
JuniperScreenos Version6.3.0r8
JuniperScreenos Version6.3.0r9
JuniperScreenos Version6.3.0r10
JuniperScreenos Version6.3.0r11
JuniperScreenos Version6.3.0r12
JuniperScreenos Version6.3.0r13
JuniperScreenos Version6.3.0r14
JuniperScreenos Version6.3.0r15
JuniperScreenos Version6.3.0r16
JuniperScreenos Version6.3.0r17
JuniperScreenos Version6.3.0r18
JuniperScreenos Version6.3.0r19
JuniperScreenos Version6.3.0r20
JuniperScreenos Version6.3.0r21
JuniperScreenos Version6.3.0r22
JuniperScreenos Version6.3.0r23
JuniperScreenos Version6.3.0r24
JuniperScreenos Version6.3.0r25
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.306
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:P/I:N/A:N
sirt@juniper.net 4.3 2.8 1.4
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.