Vulnerability Details CVE-2017-2305
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 62.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2017-2305
-
cpe:2.3:a:juniper:junos_space:-
-
cpe:2.3:a:juniper:junos_space:1.0
-
cpe:2.3:a:juniper:junos_space:1.1
-
cpe:2.3:a:juniper:junos_space:1.2
-
cpe:2.3:a:juniper:junos_space:1.3
-
cpe:2.3:a:juniper:junos_space:1.4
-
cpe:2.3:a:juniper:junos_space:11.1
-
cpe:2.3:a:juniper:junos_space:11.2
-
cpe:2.3:a:juniper:junos_space:11.3
-
cpe:2.3:a:juniper:junos_space:11.4
-
cpe:2.3:a:juniper:junos_space:12.1
-
cpe:2.3:a:juniper:junos_space:12.2
-
cpe:2.3:a:juniper:junos_space:12.3
-
cpe:2.3:a:juniper:junos_space:13.1
-
cpe:2.3:a:juniper:junos_space:13.3
-
cpe:2.3:a:juniper:junos_space:14.1
-
cpe:2.3:a:juniper:junos_space:15.1
-
cpe:2.3:a:juniper:junos_space:15.2
-
cpe:2.3:a:juniper:junos_space:16.1
-
cpe:2.3:a:juniper:junos_space:2.0