Information Leak in Junos Space by Juniper Networks
CVE-2017-2309

5.9MEDIUM

Key Information:

Vendor
CVE Published:
30 May 2017

Summary

In Junos Space by Juniper Networks, versions prior to 16.1R1, a vulnerability exists when certificate-based authentication is enabled for the Junos Space cluster. This flaw allows certain restricted web services to be accessed over the network, leading to potential exposure of sensitive information. Organizations using affected versions should ensure proper configurations and consider upgrading to mitigate this risk.

Affected Version(s)

Junos Space versions prior to 16.1R1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.