CVE-2013-6012
high
CVSS v3
—
CVSS v2
8.5
VIR risk
8.5
Description
Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows remote attackers to bypass authentication via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10593
References
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.