← back
CVE-2018-0053

vSRX Series: A local authentication vulnerability may lead to full control of a vSRX instance while the system is booting.

CVSS 6.8 MEDIUMEPSS 0.5%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Oct 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX.
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →