2024-12-08 03:06:42 +00:00

131 lines
4.4 KiB
JSON

{
"id": "CVE-2017-2321",
"sourceIdentifier": "sirt@juniper.net",
"published": "2017-04-24T15:59:00.473",
"lastModified": "2024-11-21T03:23:16.853",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks."
},
{
"lang": "es",
"value": "Una vulnerabilidad en Juniper Networks NorthStar Controller Application anterior a la versi\u00f3n 2.1.0 Service Pack 1 puede permitir a un atacante no autenticado, sin privilegios y basado en la red, provocar varias denegaciones de servicio parciales o totales de los servicios del sistema, modificaci\u00f3n de estados y archivos del sistema y divulgaci\u00f3n potencial de informaci\u00f3n sensible que puede ayudar al atacante en ataques adicionales al sistema mediante el uso de m\u00faltiples vectores de ataque, incluyendo ataques man-in-the-middle, inyecciones de archivos y ejecuci\u00f3n maliciosa de comandos que provocan condiciones de memoria fuera de l\u00edmites conduciendo a otros ataques."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 4.7
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"baseScore": 7.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:juniper:northstar_controller:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.1.0",
"matchCriteriaId": "BBCC1859-771C-44AC-A4C1-AAA6A5E6C1BF"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/97693",
"source": "sirt@juniper.net",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://kb.juniper.net/JSA10783",
"source": "sirt@juniper.net",
"tags": [
"Mitigation",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/97693",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://kb.juniper.net/JSA10783",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mitigation",
"Vendor Advisory"
]
}
]
}