CVE-2016-1265

A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.
References
Link Resource
https://kb.juniper.net/JSA10727 Vendor Advisory
https://kb.juniper.net/JSA10727 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:juniper:junos_space:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () https://kb.juniper.net/JSA10727 - Vendor Advisory () https://kb.juniper.net/JSA10727 - Vendor Advisory

Information

Published : 2017-10-13 17:29

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1265

Mitre link : CVE-2016-1265

CVE.ORG link : CVE-2016-1265


JSON object : View

Products Affected

juniper

  • junos_space
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-255

Credentials Management Errors

CWE-352

Cross-Site Request Forgery (CSRF)