8.8
CVE-2019-0017
- EPSS 0.23%
- Veröffentlicht 15.01.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:03
- Quelle sirt@juniper.net
- Teams Watchlist Login
- Unerledigt Login
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Space Version13.3 Updater1
Juniper ≫ Junos Space Version13.3 Updater2
Juniper ≫ Junos Space Version13.3 Updater3
Juniper ≫ Junos Space Version13.3 Updater4
Juniper ≫ Junos Space Version14.1 Update-
Juniper ≫ Junos Space Version14.1 Updater1
Juniper ≫ Junos Space Version14.1 Updater2
Juniper ≫ Junos Space Version14.1 Updater3
Juniper ≫ Junos Space Version15.1 Updater1
Juniper ≫ Junos Space Version15.1 Updater2
Juniper ≫ Junos Space Version15.1 Updater3
Juniper ≫ Junos Space Version15.1 Updater4
Juniper ≫ Junos Space Version15.2 Update-
Juniper ≫ Junos Space Version15.2 Updater1
Juniper ≫ Junos Space Version15.2 Updater2
Juniper ≫ Junos Space Version16.1 Update-
Juniper ≫ Junos Space Version16.1 Updater1
Juniper ≫ Junos Space Version16.1 Updater2
Juniper ≫ Junos Space Version16.1 Updater3
Juniper ≫ Junos Space Version17.1 Updater1
Juniper ≫ Junos Space Version17.2 Updater1.4
Juniper ≫ Junos Space Version18.1 Updater1
Juniper ≫ Junos Space Version18.2 Updater1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.456 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
sirt@juniper.net | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.