← volver
CVE-2018-0044

NFX Series: Insecure sshd configuration in Juniper Device Manager (JDM) and host OS

CVSS 9.8 CRITICALEPSS 1.3%
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 1.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 oct 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes". Affected releases are Juniper Networks Junos OS: 18.1 versions prior to 18.1R4 on NFX Series.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Juniper Networks · Junos OS

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →