漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
Vulnerability Description
A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1393
Vulnerability Title
Juniper Networks Support Insights Virtual Lightweight Collector 安全漏洞
Vulnerability Description
Juniper Networks Support Insights Virtual Lightweight Collector是美国瞻博网络(Juniper Networks)公司的一款网络设备遥测数据采集与运维分析辅助组件。 Juniper Networks Support Insights Virtual Lightweight Collector 3.0.94之前版本存在安全漏洞,该漏洞源于使用默认密码,可能导致攻击者完全控制设备。
CVSS Information
N/A
Vulnerability Type
N/A