VulnerabilityModified
CVE-2017-2309
This represents an information leak risk.
MEDIUM 5.9EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- juniper/junos space
- Source
- sirt@juniper.net
References
- http://www.securityfocus.com/bid/98750Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10770Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/98750Third Party Advisory, VDB Entry
- https://kb.juniper.net/JSA10770Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.