Vulnerability Name: | CVE-2018-0053 (CCN-151043) | ||||||||||||
Assigned: | 2017-11-16 | ||||||||||||
Published: | 2018-10-10 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX. | ||||||||||||
CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 5.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-0053 Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041854 Source: XF Type: UNKNOWN juniper-junos-cve20180053-sec-bypass(151043) Source: CCN Type: Juniper Networks Security Bulletin JSA10887 vSRX Series: A local authentication vulnerability may lead to full control of a vSRX instance while the system is booting. (CVE-2018-0053) Source: CONFIRM Type: Vendor Advisory https://kb.juniper.net/JSA10887 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |