← Back

CVE-2013-4689

nvd nist
Published: Oct 17, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.

Affected (44)

Products: Juniper: Junos
1 product
Junos
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
Up to 10.4
Version 11.4
Version 12.1
Version 12.1x44
Version 12.1x45
Version 12.2
Version 12.3
Version 13.1
Version 4.0
Version 4.1
Version 4.2
Version 4.3
Version 4.4
Version 5.0
Version 5.1
Version 5.2
Version 5.3
Version 5.4
Version 5.5
Version 5.6
Version 5.7
Version 6.0
Version 6.1
Version 6.2
Version 6.3
Version 6.4
Version 7.0
Version 7.1
Version 7.2
Version 7.3
Version 7.4
Version 7.5
Version 7.6
Version 8.0
Version 8.1
Version 8.2
Version 8.3
Version 8.4
Version 9.0
Version 9.1
Version 9.2
Version 9.4
Version 9.5
Version 9.6

References (8)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.