Vulnerability Name:

CCN-12438

Published:2003-06-24
Updated:2003-06-24
Summary:NetScreen could allow a remote attacker to gain unauthorized access to protected resources and services, caused by a vulnerability in the authentication mechanism, which authenticates users based on the source IP address only. If a user with a valid account authenticates to a vulnerable system, a remote attacker with the same source IP address can gain unauthorized access to the system without authenticating.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Tue Jun 24 2003 - 23:14:40 CDT
Authentication Vulnerability in NetScreen ScreenOS

Source: CCN
Type: BID-8033
NetScreen ScreenOS Same Source IP Authentication Vulnerability

Source: XF
Type: UNKNOWN
netscreen-screenos-auth-bypass(12438)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:juniper:netscreen_screenos:3.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:3.0.1r1:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:3.0.1r2:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:3.0.3:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:4.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:4.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:4.0.0::dial:*:*:*:*:*
  • OR cpe:/o:juniper:netscreen_screenos:3.0.3r1.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    juniper netscreen screenos 3.0.1
    juniper netscreen screenos 3.0.1r1
    juniper netscreen screenos 3.0.1r2
    juniper netscreen screenos 3.0.3
    juniper netscreen screenos 4.0.0
    juniper netscreen screenos 4.0.1
    juniper netscreen screenos 4.0.2
    juniper netscreen screenos 4.0.0
    juniper netscreen screenos 3.0.3r1.1