« Volver al listado

CVE-2014-3413

Estado: ModificadaCrítica (9.8)—

The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3413",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-04-05T17:29:00.253",
  "references": [
    {
      "url": "https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10627",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2014-01",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10627",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2014-01",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access."
    },
    {
      "lang": "es",
      "value": "El servidor MySQL en Juniper Networks Junos Space, en versiones anteriores a la 13.3R1.8, tiene una cuenta sin especificar con una contraseña embebida. Esto permite que atacantes remotos obtengan información sensible y, consecuentemente, obtengan control administrativo aprovechando el acceso a la base de datos."
    }
  ],
  "lastModified": "2026-06-17T00:08:08.440",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53C917DF-0507-45C8-89FE-29F400C35030"
            },
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "677B0C4D-923A-4376-85A8-56208E3728A3"
            },
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDEF52F5-ABE3-453C-9A5C-7FD5CCC18F09"
            },
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B7BBF07-791C-43FE-AC38-EB68493092BC"
            },
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5B55D33-A294-4DE2-887D-6A7E29F7EEE8"
            },
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DA50B20-F26E-4FB7-A46A-74836CF546A0"
            },
            {
              "criteria": "cpe:2.3:a:juniper:junos_space:13.3:r1.7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BA008EC-659A-43CC-9741-E765958BD824"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}