Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Contrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authentication
Vulnerability Description
An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently authenticated to. This issue affects: Juniper Networks Contrail Service Orchestration 6.0.0 versions prior to 6.0.0 Patch v3 on On-premises installations. This issue does not affect Juniper Networks Contrail Service Orchestration On-premises versions prior to 6.0.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
使用候选路径或通道进行的认证绕过
Vulnerability Title
Juniper Networks Contrail Service Orchestration 安全漏洞
Vulnerability Description
Juniper Networks Contrail Service Orchestration是美国Juniper Networks公司的一个强大的软件平台。用于连接许多企业和多租户服务提供商解决方案。 Juniper Networks Contrail Service Orchestration (CSO) 6.0.0之前版本存在安全漏洞,该漏洞源于存在一个不正确的所有权分配漏洞。攻击者利用该漏洞在不进行身份验证的情况下提升其权限,从而控制本地系统。
CVSS Information
N/A
Vulnerability Type
N/A