CVE-2017-10622
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user. This issue only affects Junos Space Network Management Platform 17.1R1 without Patch v1 and 16.1 releases prior to 16.1R3. This issue was found by an external security researcher.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: sirt@juniper.net — https://kb.juniper.net/JSA10824
References
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.