Juniper SRX series device是美国瞻博网络(Juniper Networks)公司的一系列防火墙产品。Junos OS是运行在其中的一套操作系统。 Juniper SRX系列设备上的Junos OS 12.1X46版本、12.3X48版本和15.1X49版本存在安全漏洞,该漏洞源于程序在下载防病毒更新之前,没有验证HTTPS服务器证书。攻击者可利用该漏洞实施中间人攻击,注入伪造的签名,造成拒绝服务(服务中止)或造成设备无法检测到攻击类型。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Juniper Networks | Junos OS | 12.1X46 prior to 12.3X46-D71 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-10616 | 5.3 MEDIUM | Contrail: hard coded credentials |
| CVE-2017-10617 | 5.0 MEDIUM | Contrail: XML External Entity (XXE) vulnerability |
| CVE-2017-10612 | Junos Space: Persistent Cross site scripting in Junos Space | |
| CVE-2017-10624 | Junos Space: Insufficient verification of node certificates. | |
| CVE-2017-10623 | Junos Space: Insufficient verification of cluster messages | |
| CVE-2017-10622 | Junos Space: Authentication bypass vulnerability | |
| CVE-2017-10621 | Junos OS: Denial of service vulnerability in telnetd | |
| CVE-2017-10619 | Junos: SRX cluster denial of service vulnerability in flowd due to multicast packets | |
| CVE-2017-10618 | Junos: RPD core due to BGP UPDATE with malformed optional transitive attributes | |
| CVE-2017-10615 | Junos: Potential remote code execution vulnerability in PAM | |
| CVE-2017-10614 | Junos OS: A remote unauthenticated attacker can consume large amounts of CPU and/or memory | |
| CVE-2017-10613 | Junos OS: A kernel hang may occur due to a specific loopback filter action command | |
| CVE-2016-1261 | Junos: vulnerabilities in J-Web (CVE-2016-1261) | |
| CVE-2017-10611 | Junos: EX Series PFE and MX MPC7E/8E/9E PFE crash when fetching interface stats with 'exte | |
| CVE-2017-10610 | SRX Series: Embedded ICMP may cause the flowd process to crash | |
| CVE-2017-10608 | SRX series: Junos OS: SRX series using IPv6 Sun/MS-RPC ALGs may experience flowd crash on | |
| CVE-2017-10607 | Junos: rpd core due to receipt of specially crafted BGP packet | |
| CVE-2017-10606 | SRX Series: Cryptographic weakness in SRX300 Series TPM Firmware | |
| CVE-2016-4925 | JUNOSe: Line Card Reset: processor exception 0x68616c74 (halt) task: scheduler, upon recei | |
| CVE-2016-4924 | vMX: Information leak vulnerability |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet