HIGH🇬🇧 English

CVE-2020-1676

CVSS 7.2v3.1pub. 2020-10-16upd. 2024-11-21

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security controls. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Juniper Mist Cloud Ui

    APP
    Juniper
    < 2020-09-02
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-1675HIGH8.3ten sam produkt

When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might...

CVE-2020-1677HIGH7.2ten sam produkt

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in...

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓ten sam vendor

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2015-7755CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)

CVE-2026-33771CRITICAL9.1PL ✓ten sam vendor

Słabe wymagania hasła w Juniper Networks CTP OS — przejęcie urządzenia