Vulnerability Details CVE-2018-0039
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.5%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 7.5
Products affected by CVE-2018-0039
-
cpe:2.3:a:juniper:contrail_service_orchestration:1.0.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:1.5.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:2.0.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:2.1.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:2.1.1
-
cpe:2.3:a:juniper:contrail_service_orchestration:3.0.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:3.0.1
-
cpe:2.3:a:juniper:contrail_service_orchestration:3.1.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:3.2.0
-
cpe:2.3:a:juniper:contrail_service_orchestration:3.3.0