CVE-2021-0245 Information
Description
A Use of Hard-coded Credentials vulnerability in Juniper Networks Junos OS on Junos Fusion satellite devices allows an attacker who is local to the device to elevate their privileges and take control of the device. This issue affects: Juniper Networks Junos OS Junos Fusion Satellite Devices. 16.1 versions prior to 16.1R7-S7; 17.1 versions prior to 17.1R2-S12 17.1R3-S2; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S10; 17.4 version 17.4R3 and later versions; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7 18.2R3-S3; 18.3 versions prior to 18.3R1-S7 18.3R2-S4 18.3R3-S2; 18.4 versions prior to 18.4R1-S6 18.4R2-S4 18.4R3-S1; 19.1 versions prior to 19.1R1-S5 19.1R2-S1 19.1R3; 19.2 versions prior to 19.2R1-S4 19.2R2; 19.3 versions prior to 19.3R2-S5 19.3R3; 19.4 versions prior to 19.4R1-S1 19.4R2; 20.1 versions prior to 20.1R1-S1 20.1R2. This issue does not affected Junos OS releases prior to 16.1R1 or all 19.2R3 and 19.4R3 release versions.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://kb.juniper.net/JSA11138
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: