9.3

CVE-2018-0052

If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented CLI command to enable this service. However, an undocumented CLI command allows a privileged Junos user to enable RSH service and disable PAM, and hence expose the system to unauthenticated root access. When RSH is enabled, the device is listing to RSH connections on port 514. This issue is not exploitable on platforms where Junos release is based on FreeBSD 10+. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D75 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on QFX/EX Series; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D131, 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX Series; 16.1 versions prior to 16.1R3-S9, 16.1R4-S9, 16.1R5-S4, 16.1R6-S4, 16.1R7; 16.2 versions prior to 16.2R2-S5; 17.1 versions prior to 17.1R1-S7, 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R1-S6, 17.2R2-S4, 17.2R3; 17.2X75 versions prior to 17.2X75-D110, 17.2X75-D91; 17.3 versions prior to 17.3R1-S4, 17.3R2-S2, 17.3R3; 17.4 versions prior to 17.4R1-S3, 17.4R2; 18.2X75 versions prior to 18.2X75-D5.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Version12.1x46
JuniperJunos Version12.1x46 Updated10
JuniperJunos Version12.1x46 Updated15
JuniperJunos Version12.1x46 Updated20
JuniperJunos Version12.1x46 Updated25
JuniperJunos Version12.1x46 Updated30
JuniperJunos Version12.1x46 Updated35
JuniperJunos Version12.1x46 Updated40
JuniperJunos Version12.1x46 Updated45
JuniperJunos Version12.1x46 Updated50
JuniperJunos Version12.1x46 Updated55
JuniperJunos Version12.1x46 Updated60
JuniperJunos Version12.1x46 Updated65
JuniperJunos Version12.3
JuniperJunos Version12.3 Updater1
JuniperJunos Version12.3 Updater11
JuniperJunos Version12.3 Updater2
JuniperJunos Version12.3 Updater3
JuniperJunos Version12.3 Updater4
JuniperJunos Version12.3 Updater5
JuniperJunos Version12.3 Updater6
JuniperJunos Version12.3 Updater7
JuniperJunos Version12.3 Updater8
JuniperJunos Version12.3 Updater9
JuniperJunos Version12.3x48
JuniperJunos Version12.3x48 Updated10
JuniperJunos Version12.3x48 Updated15
JuniperJunos Version12.3x48 Updated20
JuniperJunos Version12.3x48 Updated25
JuniperJunos Version12.3x48 Updated30
JuniperJunos Version12.3x48 Updated35
JuniperJunos Version12.3x48 Updated40
JuniperJunos Version12.3x48 Updated45
JuniperJunos Version12.3x48 Updated50
JuniperJunos Version12.3x48 Updated55
JuniperJunos Version12.3x48 Updated60
JuniperJunos Version12.3x48 Updated65
JuniperJunos Version12.3x48 Updated70
JuniperJunos Version14.1x53
JuniperJunos Version14.1x53 Updated10
JuniperJunos Version14.1x53 Updated121
JuniperJunos Version14.1x53 Updated15
JuniperJunos Version14.1x53 Updated16
JuniperJunos Version14.1x53 Updated25
JuniperJunos Version14.1x53 Updated26
JuniperJunos Version14.1x53 Updated27
JuniperJunos Version14.1x53 Updated30
JuniperJunos Version14.1x53 Updated35
JuniperJunos Version14.1x53 Updated40
JuniperJunos Version14.1x53 Updated42
JuniperJunos Version14.1x53 Updated43
JuniperJunos Version14.1x53 Updated44
JuniperJunos Version14.1x53 Updated45
JuniperJunos Version14.1x53 Updated46
JuniperJunos Version15.1
JuniperJunos Version15.1 Updater1
JuniperJunos Version15.1 Updater2
JuniperJunos Version15.1 Updater3
JuniperJunos Version15.1 Updater6-s6
JuniperJunos Version15.1 Updater7
JuniperJunos Version15.1x49
JuniperJunos Version15.1x49 Updated10
JuniperJunos Version15.1x49 Updated100
JuniperJunos Version15.1x49 Updated110
JuniperJunos Version15.1x49 Updated120
JuniperJunos Version15.1x49 Updated140
JuniperJunos Version15.1x49 Updated20
JuniperJunos Version15.1x49 Updated30
JuniperJunos Version15.1x49 Updated35
JuniperJunos Version15.1x49 Updated40
JuniperJunos Version15.1x49 Updated45
JuniperJunos Version15.1x49 Updated50
JuniperJunos Version15.1x49 Updated55
JuniperJunos Version15.1x49 Updated60
JuniperJunos Version15.1x49 Updated65
JuniperJunos Version15.1x49 Updated70
JuniperJunos Version15.1x49 Updated75
JuniperJunos Version15.1x49 Updated80
JuniperJunos Version15.1x49 Updated90
JuniperJunos Version15.1x53
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated50
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated51
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated52
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated55
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated57
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53 Updated58
   JuniperEx2300 Version-
   JuniperEx3400 Version-
JuniperJunos Version15.1x53
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated10
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated20
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated21
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated30
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated32
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated33
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated34
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated50
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated60
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated61
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated62
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated63
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated64
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated65
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53 Updated66
   JuniperQfx10000 Version-
JuniperJunos Version15.1x53
   JuniperQfx5110 Version-
   JuniperQfx5200 Version-
JuniperJunos Version15.1x53 Updated210
   JuniperQfx5110 Version-
   JuniperQfx5200 Version-
JuniperJunos Version15.1x53 Updated230
   JuniperQfx5110 Version-
   JuniperQfx5200 Version-
JuniperJunos Version15.1x53 Updated231
   JuniperQfx5110 Version-
   JuniperQfx5200 Version-
JuniperJunos Version15.1x53 Updated232
   JuniperQfx5110 Version-
   JuniperQfx5200 Version-
JuniperJunos Version15.1x53 Updated30
   JuniperQfx5110 Version-
   JuniperQfx5200 Version-
JuniperJunos Version15.1x53
   JuniperNfx150 Version-
   JuniperNfx250 Version-
JuniperJunos Version15.1x53 Updated40
   JuniperNfx150 Version-
   JuniperNfx250 Version-
JuniperJunos Version15.1x53 Updated45
   JuniperNfx150 Version-
   JuniperNfx250 Version-
JuniperJunos Version15.1x53 Updated490
   JuniperNfx150 Version-
   JuniperNfx250 Version-
JuniperJunos Version16.1
JuniperJunos Version16.1 Updater1
JuniperJunos Version16.1 Updater2
JuniperJunos Version16.1 Updater3
JuniperJunos Version16.1 Updater4-s9
JuniperJunos Version16.1 Updater5-s4
JuniperJunos Version16.1 Updater6-s4
JuniperJunos Version16.1 Updater7
JuniperJunos Version16.2
JuniperJunos Version16.2 Updater1
JuniperJunos Version17.1
JuniperJunos Version17.1 Updater2-s7
JuniperJunos Version17.1 Updater3
JuniperJunos Version17.2
JuniperJunos Version17.2 Updater1
JuniperJunos Version17.2 Updater2
JuniperJunos Version17.2x75
JuniperJunos Version17.2x75 Updated91
JuniperJunos Version17.3
JuniperJunos Version17.3 Updater2-s2
JuniperJunos Version17.3 Updater3
JuniperJunos Version17.4
JuniperJunos Version17.4 Updater2
JuniperJunos Version18.2x75
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.91% 0.917
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
sirt@juniper.net 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.