ID

VAR-202104-0586


CVE

CVE-2021-0260


TITLE

Juniper Networks Junos OS Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202104-1018

DESCRIPTION

An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Control Sphere, or write actions to OIDs that support write operations, against the device without authentication. This issue affects: Juniper Networks Junos OS: 17.2 version 17.2R1 and later versions; 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S12, 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S6, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 17.2R1. The operating system provides a secure programming interface and Junos SDK. There is a security vulnerability in Junos OS, and there is no relevant information about this vulnerability at present, please pay attention to CNNVD or manufacturer announcements at any time

Trust: 1.08

sources: NVD: CVE-2021-0260 // VULHUB: VHN-372162 // VULMON: CVE-2021-0260

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:19.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:17.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:18.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:18.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:18.4

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:19.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:17.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:19.1

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:17.4

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:18.1

Trust: 1.0

sources: NVD: CVE-2021-0260

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-0260
value: HIGH

Trust: 1.0

sirt@juniper.net: CVE-2021-0260
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202104-1018
value: HIGH

Trust: 0.6

VULHUB: VHN-372162
value: HIGH

Trust: 0.1

VULMON: CVE-2021-0260
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-0260
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-372162
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sirt@juniper.net: CVE-2021-0260
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 3.4
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-372162 // VULMON: CVE-2021-0260 // CNNVD: CNNVD-202104-1018 // NVD: CVE-2021-0260 // NVD: CVE-2021-0260

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-285

Trust: 1.0

problemtype:CWE-497

Trust: 1.0

sources: NVD: CVE-2021-0260

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202104-1018

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202104-1018

PATCH

title:Juniper Networks Junos OS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=148042

Trust: 0.6

sources: CNNVD: CNNVD-202104-1018

EXTERNAL IDS

db:NVDid:CVE-2021-0260

Trust: 1.8

db:JUNIPERid:JSA11151

Trust: 1.8

db:CNNVDid:CNNVD-202104-1018

Trust: 0.6

db:VULHUBid:VHN-372162

Trust: 0.1

db:VULMONid:CVE-2021-0260

Trust: 0.1

sources: VULHUB: VHN-372162 // VULMON: CVE-2021-0260 // CNNVD: CNNVD-202104-1018 // NVD: CVE-2021-0260

REFERENCES

url:https://kb.juniper.net/jsa11151

Trust: 1.8

url:https://vigilance.fr/vulnerability/junos-os-multiple-vulnerabilities-35081

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2021-0260

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/863.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-372162 // VULMON: CVE-2021-0260 // CNNVD: CNNVD-202104-1018 // NVD: CVE-2021-0260

SOURCES

db:VULHUBid:VHN-372162
db:VULMONid:CVE-2021-0260
db:CNNVDid:CNNVD-202104-1018
db:NVDid:CVE-2021-0260

LAST UPDATE DATE

2024-11-23T22:29:16.875000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-372162date:2022-09-20T00:00:00
db:VULMONid:CVE-2021-0260date:2021-04-28T00:00:00
db:CNNVDid:CNNVD-202104-1018date:2022-09-21T00:00:00
db:NVDid:CVE-2021-0260date:2024-11-21T05:42:20.517

SOURCES RELEASE DATE

db:VULHUBid:VHN-372162date:2021-04-22T00:00:00
db:VULMONid:CVE-2021-0260date:2021-04-22T00:00:00
db:CNNVDid:CNNVD-202104-1018date:2021-04-14T00:00:00
db:NVDid:CVE-2021-0260date:2021-04-22T20:15:09.667