| Vulnerability Name: | CVE-2013-5097 (CCN-86474) | ||||||||
| Assigned: | 2013-08-15 | ||||||||
| Published: | 2013-08-15 | ||||||||
| Updated: | 2013-09-12 | ||||||||
| Summary: | Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462. | ||||||||
| CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-5097 Source: CCN Type: JSA10585 Junos Space: Multiple Vulnerabilities Source: CONFIRM Type: Patch http://kb.juniper.net/JSA10585 Source: CCN Type: SA54549 Juniper Junos Space Multiple Vulnerabilities Source: CCN Type: BID-61795 Juniper Networks JUNOS Space CVE-2013-5097 Multiple Information Disclosure Vulnerabilities Source: SECTRACK Type: UNKNOWN 1028923 Source: XF Type: UNKNOWN juniper-junos-cve20135097-info-disc(86474) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||