CVE-2016-1265
Summary
| CVE | CVE-2016-1265 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-13 17:29:00 UTC |
| Updated | 2019-10-09 23:17:00 UTC |
| Description | A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected. |
Risk And Classification
Problem Types: CWE-255 | CWE-352 | CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Juniper | Junos Space | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2016-04 Security Bulletin: Junos Space: Multiple privilege escalation vulnerabilities in Junos Space - Juniper Networks | CONFIRM | kb.juniper.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.