Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown
CVE-2017-2305
Disclosure Date: May 30, 2017 (last updated November 26, 2024)
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
0
Attacker Value
Unknown
CVE-2017-2307
Disclosure Date: May 30, 2017 (last updated November 26, 2024)
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.
0
Attacker Value
Unknown
CVE-2017-2309
Disclosure Date: May 30, 2017 (last updated November 26, 2024)
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
0
Attacker Value
Unknown
CVE-2016-4930
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
0
Attacker Value
Unknown
CVE-2016-4929
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
0
Attacker Value
Unknown
CVE-2016-4927
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
0
Attacker Value
Unknown
CVE-2016-4928
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
0
Attacker Value
Unknown
CVE-2016-4931
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
0
Attacker Value
Unknown
CVE-2016-4926
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.
0
Attacker Value
Unknown
CVE-2016-1265
Disclosure Date: April 13, 2016 (last updated November 26, 2024)
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.
0