| Vulnerability Name: | CVE-2018-0044 (CCN-151035) | ||||||||||||
| Assigned: | 2017-11-16 | ||||||||||||
| Published: | 2018-10-10 | ||||||||||||
| Updated: | 2019-10-09 | ||||||||||||
| Summary: | An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes". Affected releases are Juniper Networks Junos OS: 18.1 versions prior to 18.1R4 on NFX Series. | ||||||||||||
| CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-287 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-0044 Source: BID Type: Third Party Advisory, VDB Entry 105565 Source: CCN Type: BID-105565 Juniper Device Manager CVE-2018-0044 Unauthorized Access Vulnerability Source: XF Type: UNKNOWN juniper-junos-cve20180044-unauth-access(151035) Source: CCN Type: Juniper Networks Security Bulletin JSA10878 NFX Series: Insecure sshd configuration in Juniper Device Manager (JDM) and host OS (CVE-2018-0044) Source: CONFIRM Type: Vendor Advisory https://kb.juniper.net/JSA10878 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||