Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-0220


The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a successful attack includes, but is not limited to, obtaining access to other servers connected to the Junos Space Management Platform. This issue affects Juniper Networks Junos Space versions prior to 20.3R1.


Published

2021-01-15T18:15:15.667

Last Modified

2024-11-21T05:42:14.073

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-257
  • Type: Primary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application juniper junos_space 1.0 Yes
Application juniper junos_space 1.1 Yes
Application juniper junos_space 1.2 Yes
Application juniper junos_space 1.3 Yes
Application juniper junos_space 1.4 Yes
Application juniper junos_space 2.0 Yes
Application juniper junos_space 11.1 Yes
Application juniper junos_space 11.2 Yes
Application juniper junos_space 11.3 Yes
Application juniper junos_space 11.4 Yes
Application juniper junos_space 12.1 Yes
Application juniper junos_space 12.2 Yes
Application juniper junos_space 12.3 Yes
Application juniper junos_space 13.1 Yes
Application juniper junos_space 13.1 Yes
Application juniper junos_space 13.3 Yes
Application juniper junos_space 14.1 Yes
Application juniper junos_space 15.1 Yes
Application juniper junos_space 15.1 Yes
Application juniper junos_space 15.1 Yes
Application juniper junos_space 15.2 Yes
Application juniper junos_space 16.1 Yes
Application juniper junos_space 17.1 Yes
Application juniper junos_space 17.2 Yes
Application juniper junos_space 17.2 Yes
Application juniper junos_space 18.1 Yes
Application juniper junos_space 18.1r1 Yes
Application juniper junos_space 18.2 Yes
Application juniper junos_space 18.3 Yes
Application juniper junos_space 18.4 Yes
Application juniper junos_space 19.1 Yes
Operating System juniper junos_space 15.1 Yes
Operating System juniper junos_space 15.2 Yes
Operating System juniper junos_space 16.1 Yes
Operating System juniper junos_space 17.2 Yes
Operating System juniper junos_space 18.1 Yes
Operating System juniper junos_space 18.2 Yes
Operating System juniper junos_space 18.3 Yes
Operating System juniper junos_space 18.4 Yes
Operating System juniper junos_space 19.1 Yes
Operating System juniper junos_space 19.2 Yes
Operating System juniper junos_space 19.3 Yes
Operating System juniper junos_space 19.4 Yes
Operating System juniper junos_space 20.1 Yes

References