VulnerabilityModified
CVE-2017-2308
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
MEDIUM 6.5EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- juniper/junos space
- Source
- sirt@juniper.net
References
- http://www.securityfocus.com/bid/98755Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10770Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/98755Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10770Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.