Vulnerability Details CVE-2017-2305
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2017-2305
-
cpe:2.3:a:juniper:junos_space:-
-
cpe:2.3:a:juniper:junos_space:1.0
-
cpe:2.3:a:juniper:junos_space:1.1
-
cpe:2.3:a:juniper:junos_space:1.2
-
cpe:2.3:a:juniper:junos_space:1.3
-
cpe:2.3:a:juniper:junos_space:1.4
-
cpe:2.3:a:juniper:junos_space:11.1
-
cpe:2.3:a:juniper:junos_space:11.2
-
cpe:2.3:a:juniper:junos_space:11.3
-
cpe:2.3:a:juniper:junos_space:11.4
-
cpe:2.3:a:juniper:junos_space:12.1
-
cpe:2.3:a:juniper:junos_space:12.2
-
cpe:2.3:a:juniper:junos_space:12.3
-
cpe:2.3:a:juniper:junos_space:13.1
-
cpe:2.3:a:juniper:junos_space:13.3
-
cpe:2.3:a:juniper:junos_space:14.1
-
cpe:2.3:a:juniper:junos_space:15.1
-
cpe:2.3:a:juniper:junos_space:15.2
-
cpe:2.3:a:juniper:junos_space:16.1
-
cpe:2.3:a:juniper:junos_space:2.0