Juniper Junos Space < 13.3R1.8 Multiple Vulnerabilities (JSA10627)

critical Nessus Plugin ID 80195

Synopsis

The remote device is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the remote Junos Space version is prior to 13.3R1.8. It is, therefore, affected by multiple vulnerabilities in bundled third party software components :

- Multiple vulnerabilities in RedHat JBoss application server. (CVE-2010-0738, CVE-2010-1428, CVE-2010-1429, CVE-2011-5245, CVE-2012-0818)

- Multiple vulnerabilities in Oracle Java SE JDK.
(CVE-2012-3143, CVE-2013-1537, CVE-2013-1557, CVE-2013-2422)

- Multiple vulnerabilities in Oracle MySQL server.
(CVE-2013-1502, CVE-2013-1511, CVE-2013-1532, CVE-2013-1544, CVE-2013-2375, CVE-2013-2376, CVE-2013-2389, CVE-2013-2391, CVE-2013-2392, CVE-2013-3783, CVE-2013-3793, CVE-2013-3794, CVE-2013-3801, CVE-2013-3802, CVE-2013-3804, CVE-2013-3805, CVE-2013-3808, CVE-2013-3809, CVE-2013-3812, CVE-2013-3839)

- Multiple vulnerabilities in Apache HTTP Server.
(CVE-2013-1862, CVE-2013-1896)

- Known hard-coded MySQL credentials. (CVE-2014-3413)

Solution

Upgrade to Junos Space 13.3R1.8 or later.

See Also

https://www.tenable.com/security/research/tra-2014-01

https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10627

Plugin Details

Severity: Critical

ID: 80195

File Name: juniper_space_jsa10627.nasl

Version: 1.10

Type: local

Published: 12/22/2014

Updated: 5/25/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-3413

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:juniper:junos_space

Required KB Items: Host/Junos_Space/version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/14/2014

Vulnerability Publication Date: 4/27/2010

CISA Known Exploited Vulnerability Due Dates: 6/15/2022

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (JBoss JMX Console Deployer Upload and Execute)

ExploitHub (EH-12-132)

Reference Information

CVE: CVE-2010-0738, CVE-2010-1428, CVE-2010-1429, CVE-2011-5245, CVE-2012-0818, CVE-2012-3143, CVE-2013-1502, CVE-2013-1511, CVE-2013-1532, CVE-2013-1537, CVE-2013-1544, CVE-2013-1557, CVE-2013-1862, CVE-2013-1896, CVE-2013-2375, CVE-2013-2376, CVE-2013-2389, CVE-2013-2391, CVE-2013-2392, CVE-2013-2422, CVE-2013-3783, CVE-2013-3793, CVE-2013-3794, CVE-2013-3801, CVE-2013-3802, CVE-2013-3804, CVE-2013-3805, CVE-2013-3808, CVE-2013-3809, CVE-2013-3812, CVE-2013-3839, CVE-2014-3413

BID: 39710, 51748, 51766, 56055, 59170, 59194, 59201, 59207, 59209, 59211, 59224, 59227, 59228, 59229, 59239, 59242, 59826, 61129, 61210, 61222, 61227, 61244, 61249, 61256, 61260, 61264, 61269, 61272, 63109