Juniper Contrail Service Orchestration(CSO)是美国瞻博网络(Juniper Networks)公司的一套用于在云CPE集中部署模型中设计和部署网络服务的产品。 Juniper CSO 3.3.0之前版本中存在安全漏洞,该漏洞源于程序对Keystone服务的访问使用了硬编码凭证。攻击者可利用该漏洞访问存储在keystone中的信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Juniper Networks | Contrail Service Orchestration | unspecified ~ 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-0024 | Junos OS: A privilege escalation vulnerability exists where authenticated users with shell | |
| CVE-2018-0025 | Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through | |
| CVE-2018-0026 | Junos OS: Stateless IP firewall filter rules stop working as expected after reboot or upgr | |
| CVE-2018-0027 | Junos OS: Receipt of malformed RSVP packet may lead to RPD denial of service | |
| CVE-2018-0029 | Junos OS: Kernel crash (vmcore) during broadcast storm after enabling 'monitor traffic int | |
| CVE-2018-0030 | Junos OS: MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) and PTX1K: Line card may crash upon receipt | |
| CVE-2018-0031 | Junos OS: Receipt of specially crafted UDP packets over MPLS may bypass stateless IP firew | |
| CVE-2018-0032 | Junos OS: RPD crash when receiving a crafted BGP UPDATE | |
| CVE-2018-0034 | Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core | |
| CVE-2018-0035 | Junos OS: QFX5200 and QFX10002: Unintended ONIE partition was shipped with certain Junos O | |
| CVE-2018-0037 | Junos OS: RPD daemon crashes due to receipt of crafted BGP NOTIFICATION messages | |
| CVE-2018-0039 | Contrail Service Orchestration: Hardcoded credentials for Grafana service | |
| CVE-2018-0040 | Contrail Service Orchestration: hardcoded cryptographic certificates and keys |
No comments yet