« Volver al listado

CVE-2017-2321

Estado: ModificadaAlta (8.6)—

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2321",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "NorthStar Controller Application",
          "versions": [
            {
              "status": "affected",
              "version": "prior to version 2.1.0 Service Pack 1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-24T15:59:00.473",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/97693",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "https://kb.juniper.net/JSA10783",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "http://www.securityfocus.com/bid/97693",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kb.juniper.net/JSA10783",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en Juniper Networks NorthStar Controller Application anterior a la versión 2.1.0 Service Pack 1 puede permitir a un atacante no autenticado, sin privilegios y basado en la red, provocar varias denegaciones de servicio parciales o totales de los servicios del sistema, modificación de estados y archivos del sistema y divulgación potencial de información sensible que puede ayudar al atacante en ataques adicionales al sistema mediante el uso de múltiples vectores de ataque, incluyendo ataques man-in-the-middle, inyecciones de archivos y ejecución maliciosa de comandos que provocan condiciones de memoria fuera de límites conduciendo a otros ataques."
    }
  ],
  "lastModified": "2026-06-17T01:15:57.647",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:juniper:northstar_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBCC1859-771C-44AC-A4C1-AAA6A5E6C1BF",
              "versionEndIncluding": "2.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}