|
246771
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-0042
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246772
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to in…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0041
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246773
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized ac…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0040
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246774
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorize…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0039
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246775
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthori…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0038
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246776
|
5.9 |
MEDIUM
Network
|
juniper
|
junos
|
Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash. When RPD is unavailable, routing updates cannot be processed which can lead to an ext…
|
CWE-20
Improper Input Validation
|
CVE-2018-0027
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246777
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages. By continuously sending crafted BGP NOTI…
|
CWE-20
Improper Input Validation
|
CVE-2018-0037
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246778
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
QFX5200 and QFX10002 devices that have been shipped with Junos OS 15.1X53-D21, 15.1X53-D30, 15.1X53-D31, 15.1X53-D32, 15.1X53-D33 and 15.1X53-D60 or have been upgraded to these releases using the .bi…
|
NVD-CWE-noinfo
|
CVE-2018-0035
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246779
|
5.9 |
MEDIUM
Network
|
juniper
|
junos
|
A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core the JDHCPD daemon by sending a crafted IPv6 packet to the system. This issue i…
|
CWE-20
Improper Input Validation
|
CVE-2018-0034
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246780
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of the same crafted BGP UPDATE can result in an extended denial of service condition…
|
CWE-20
Improper Input Validation
|
CVE-2018-0032
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|