• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-0027
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.4 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
CVE-2019-0026
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.4 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
CVE-2019-0025
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.4 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
CVE-2019-0024
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.4 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
CVE-2019-0023
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.4 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
CVE-2019-0022
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
9.8 CRITICAL
Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.
CVE-2019-0021
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.5 MEDIUM
On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
CVE-2019-0020
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
9.8 CRITICAL
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.
CVE-2019-0019
2021-10-28
N/A
7.5 HIGH
When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S4, 16.1R7-S5; 16.2 versions prior to 16.2R2-S9, 16.2R3; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R3-S1; 17.3 versions prior to 17.3R3-S3, 17.3R3-S4, 17.3R4; 17.4 versions prior to 17.4R1-S7, 17.4R2-S3, 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S4, 18.1R4; 18.2 versions prior to 18.2R2-S2, 18.2R2-S3, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2. This issue does not affect Junos releases prior to 16.1R1.
CVE-2019-0018
Atp700, Juniper
Junos, Ex2300, Ex3400, Srx100, Srx110, Srx1400, Srx1500, Srx210, Srx220, Srx240
2019-10-09
N/A
5.4 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
« Previous 1 … 6,718 6,719 6,720 6,721 6,722 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE