Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0057


An improper authorization weakness in Juniper Networks Junos OS allows a local authenticated attacker to bypass regular security controls to access the Junos Device Manager (JDM) application and take control of the system. This issue affects: Juniper Networks Junos OS versions prior to 18.2R1, 18.2X75-D5.


Published

2019-10-09T20:15:16.690

Last Modified

2024-11-21T04:16:09.287

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper junos ≤ 18.1 Yes
Operating System juniper junos 18.2 Yes
Operating System juniper junos 18.2x75 Yes
Hardware juniper nfx150 - No
Hardware juniper nfx250 - No

References