Security restrictions bypass in Junos OS - CVE-2018-0044

 

Security restrictions bypass in Junos OS - CVE-2018-0044

Published: October 10, 2018 / Updated: October 11, 2018


Vulnerability identifier: #VU15306
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0044
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to an insecure SSHD configuration with the PermitEmptyPasswords option set to "yes" in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices. A remote attacker can bypass security restrictions to conduct further attacks.


Affected software

Junos OS

How to mitigate CVE-2018-0044

Update to version 18.1R4.

Junos OS - update to 18.1R4

External References

Related Security Bulletins