This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This issue affects: Juniper Networks Junos OS versions prior to 19.1R1 on NFX Series. No other platforms besides NFX Series devices are affected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HJuniper Junos
OSJuniper19.1< 19.1Juniper Nfx150
HWJuniperall versionsJuniper Nfx250
HWJuniperall versionsJuniper Nfx350
HWJuniperall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same product
RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)
CVE-2024-21591CRITICAL9.8PL ✓same product
Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root
CVE-2021-0254CRITICAL9.8PL ✓same product
Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS
CVE-2021-0211CRITICAL10.0PL ✓same product
Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message
CVE-2020-1654CRITICAL9.8PL ✓same product
RCE i DoS w Juniper SRX przez podatność usługi ICAP redirect