Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-6448


Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restrictions and execute arbitrary Python code via vectors involving shell access.


Published

2020-01-15T18:15:11.540

Last Modified

2024-11-21T02:14:24.297

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper junos 13.2 Yes
Operating System juniper junos 13.2 Yes
Operating System juniper junos 13.2 Yes
Operating System juniper junos 13.2 Yes
Operating System juniper junos 13.2 Yes
Operating System juniper junos 13.2x51 Yes
Operating System juniper junos 13.2x52 Yes
Operating System juniper junos 13.3 Yes
Operating System juniper junos 13.3 Yes
Operating System juniper junos 13.3 Yes

References