SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-2321

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services,…

HIGH 8.6EPSS 1.45%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.

CVSS 3.0
8.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
EPSS
1.45% probability · 72th percentile
CISA KEV
Not listed
Affected
juniper/northstar controller
Source
sirt@juniper.net

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.