← Back

CVE-2019-0039

nvd nist
Published: Apr 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting techniques. Additionally, administrators who do not enforce a strong password policy can increase the likelihood of success from brute force attacks. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D49; 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D160; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D495, 15.1X53-D591, 15.1X53-D69; 16.1 versions prior to 16.1R3-S10, 16.1R4-S12, 16.1R6-S6, 16.1R7-S3; 16.1X65 versions prior to 16.1X65-D49; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S2; 17.4 versions prior to 17.4R1-S6, 17.4R2-S2; 18.1 versions prior to 18.1R2-S4, 18.1R3-S1; 18.2 versions prior to 18.2R1-S5; 18.2X75 versions prior to 18.2X75-D30; 18.3 versions prior to 18.3R1-S1.

Affected (15)

Products: Juniper: Junos
1 product
Junos
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Juniper
From 14.1x53 to 14.1x53-d49
From 15.1 to 15.1f6-s12
From 15.1x49 to 15.1x49-d160
From 15.1x53 to 15.1x53-d236
From 16.1 to 16.1r3-s10
From 16.1x65 to 16.1x65-d49
From 16.2 to 16.2r2-s7
From 17.1 to 17.1r2-s10
From 17.2 to 17.2r1-s8
From 17.3 to 17.3r3-s2
From 17.4 to 17.4r1-s6
From 18.1 to 18.1r2-s4
From 18.2 to 18.2r1-s5
From 18.2x75 to 18.2x75-d30
From 18.3 to 18.3r1-s1

References (4)

Source: sirt@juniper.net
Broken LinkThird Party AdvisoryVDB Entry
Source: sirt@juniper.net
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.