{"api_version":"1","generated_at":"2026-07-23T05:02:32+00:00","cve":"CVE-2017-2317","urls":{"html":"https://cve.report/CVE-2017-2317","api":"https://cve.report/api/cve/CVE-2017-2317.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-2317","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-2317"},"summary":{"title":"CVE-2017-2317","description":"A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker.","state":"PUBLISHED","assigner":"juniper","published_at":"2017-04-24 15:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","denials of service, potential information disclosure or modification of system states"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.6","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://kb.juniper.net/JSA10783","name":"https://kb.juniper.net/JSA10783","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"],"title":"2017-04 Security Bulletin: Multiple Vulnerabilities in NorthStar Controller Application before version 2.1.0 Service Pack 1. - Juniper Networks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/97652","name":"http://www.securityfocus.com/bid/97652","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Juniper NorthStar Controller Application CVE-2017-2317 Unspecified Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-2317","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2317","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Juniper Networks","product":"NorthStar Controller Application","version":"affected prior to version 2.1.0 Service Pack 1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"2317","vulnerable":"1","versionEndIncluding":"2.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"juniper","cpe5":"northstar_controller","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T13:48:05.212Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kb.juniper.net/JSA10783"},{"name":"97652","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97652"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"NorthStar Controller Application","vendor":"Juniper Networks","versions":[{"status":"affected","version":"prior to version 2.1.0 Service Pack 1"}]}],"datePublic":"2017-04-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker."}],"problemTypes":[{"descriptions":[{"description":"denials of service, potential information disclosure or modification of system states","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-04-25T09:57:01.000Z","orgId":"8cbe9d5a-a066-4c94-8978-4b15efeae968","shortName":"juniper"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://kb.juniper.net/JSA10783"},{"name":"97652","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97652"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"sirt@juniper.net","ID":"CVE-2017-2317","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"NorthStar Controller Application","version":{"version_data":[{"version_value":"prior to version 2.1.0 Service Pack 1"}]}}]},"vendor_name":"Juniper Networks"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"denials of service, potential information disclosure or modification of system states"}]}]},"references":{"reference_data":[{"name":"https://kb.juniper.net/JSA10783","refsource":"CONFIRM","url":"https://kb.juniper.net/JSA10783"},{"name":"97652","refsource":"BID","url":"http://www.securityfocus.com/bid/97652"}]}}}},"cveMetadata":{"assignerOrgId":"8cbe9d5a-a066-4c94-8978-4b15efeae968","assignerShortName":"juniper","cveId":"CVE-2017-2317","datePublished":"2017-04-24T15:00:00.000Z","dateReserved":"2016-12-01T00:00:00.000Z","dateUpdated":"2024-08-05T13:48:05.212Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-04-24 15:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","denials of service, potential information disclosure or modification of system states"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:juniper:northstar_controller:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.0","matchCriteriaId":"BBCC1859-771C-44AC-A4C1-AAA6A5E6C1BF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"2317","Ordinal":"1","Title":"CVE-2017-2317","CVE":"CVE-2017-2317","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"2317","Ordinal":"1","NoteData":"A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker.","Type":"Description","Title":"CVE-2017-2317"},{"CveYear":"2017","CveId":"2317","Ordinal":"2","NoteData":"2017-04-24","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"2317","Ordinal":"3","NoteData":"2017-04-25","Type":"Other","Title":"Modified"}]}}}