Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 863804.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://kb.juniper.net/JSA10585 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/61794 - | |
References | () http://www.securitytracker.com/id/1028923 - |
Information
Published : 2013-08-16 14:01
Updated : 2024-11-21 01:57
NVD link : CVE-2013-5096
Mitre link : CVE-2013-5096
CVE.ORG link : CVE-2013-5096
JSON object : View
Products Affected
juniper
- junos_space
- junos_space_ja1500_appliance
- junos_space_virtual_appliance
CWE
CWE-264
Permissions, Privileges, and Access Controls