SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0016

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user.

MEDIUM 6.5EPSS 0.93%

Does this matter?

Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.

Description

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.93% probability · 59th percentile
CISA KEV
Not listed
Affected
juniper/junos space
Source
sirt@juniper.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.