Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-2341


An insufficient authentication vulnerability on platforms where Junos OS instances are run in a virtualized environment, may allow unprivileged users on the Junos OS instance to gain access to the host operating environment, and thus escalate privileges. Affected releases are Juniper Networks Junos OS 14.1X53 prior to 14.1X53-D40 on QFX5110, QFX5200, QFX10002, QFX10008, QFX10016, EX4600 and NFX250; 15.1 prior to 15.1R5 on EX4600; 15.1X49 prior to 15.1X49-D70 on vSRX, SRX1500, SRX4100, SRX4200; 16.1 prior to 16.1R2 on EX4600, ACX5000 series. This issue does not affect vMX. No other Juniper Networks products or platforms are affected by this issue.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.8, requiring local system access to exploit with relatively low complexity without requiring user interaction requiring only low-level privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 13 products from juniper, from juniper, from juniper and 10 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2017, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2017-07-17T13:18:24.237

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper qfx5110 - No
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper qfx5200 - No
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper qfx10002 - No
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper qfx10008 - No
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper qfx10016 - No
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper ex4600 - No
Operating System juniper junos 14.1x53 Yes
Operating System juniper junos 14.1x53-d10 Yes
Operating System juniper junos 14.1x53-d15 Yes
Operating System juniper junos 14.1x53-d25 Yes
Operating System juniper junos 14.1x53-d26 Yes
Operating System juniper junos 14.1x53-d27 Yes
Operating System juniper junos 14.1x53-d30 Yes
Operating System juniper junos 14.1x53-d35 Yes
Hardware juniper nfx250 - No
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Operating System juniper junos 15.1 Yes
Hardware juniper ex4600 - No
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Hardware juniper vsrx - No
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Hardware juniper srx1500 - No
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Hardware juniper srx4100 - No
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Operating System juniper junos 15.1x49 Yes
Hardware juniper srx4200 - No
Operating System juniper junos 16.1 Yes
Operating System juniper junos 16.1 Yes
Hardware juniper ex4600 - No
Operating System juniper junos 16.1 Yes
Operating System juniper junos 16.1 Yes
Hardware juniper acx5000 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For juniper's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.