// For flags

CVE-2018-0001

Junos: Unauthenticated Remote Code Execution through J-Web interface

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific PHP URLs within the context of the J-Web process. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D67; 12.3 versions prior to 12.3R12-S5; 12.3X48 versions prior to 12.3X48-D35; 14.1 versions prior to 14.1R8-S5, 14.1R9; 14.1X53 versions prior to 14.1X53-D44, 14.1X53-D50; 14.2 versions prior to 14.2R7-S7, 14.2R8; 15.1 versions prior to 15.1R3; 15.1X49 versions prior to 15.1X49-D30; 15.1X53 versions prior to 15.1X53-D70.

Un atacante remoto no autenticado podría ejecutar código explotando un defecto de uso de memoria previamente liberada en versiones antiguas de PHP mediante la inyección de datos manipulados a través de URL PHP específicas en el contexto del proceso J-Web. Las distribuciones afectadas son Juniper Networks Junos OS: 12.1X46 anterior a 12.1X46-D67; 12.3 anterior a 12.3R12-S5; 12.3X48 anterior a 12.3X48-D35; 14.1 anterior a 14.1R8-S5, 14.1R9; 14.1X53 anterior a 14.1X53-D44, 14.1X53-D50; 14.2 anterior a 14.2R7-S7, 14.2R8; 15.1 anterior a 15.1R3; 15.1X49 anterior a 15.1X49-D30; 15.1X53 anterior a 15.1X53-D70.

*Credits: Cure53 for responsibly reporting this vulnerability.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-16 CVE Reserved
  • 2018-01-10 CVE Published
  • 2023-12-21 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d10
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d15
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d20
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d25
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d30
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d35
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d40
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d45
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d50
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d55
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d60
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.1x46
Search vendor "Juniper" for product "Junos" and version "12.1x46"
d65
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3x48
Search vendor "Juniper" for product "Junos" and version "12.3x48"
d10
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3x48
Search vendor "Juniper" for product "Junos" and version "12.3x48"
d15
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3x48
Search vendor "Juniper" for product "Junos" and version "12.3x48"
d20
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3x48
Search vendor "Juniper" for product "Junos" and version "12.3x48"
d25
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3x48
Search vendor "Juniper" for product "Junos" and version "12.3x48"
d30
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d10
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d20
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x49
Search vendor "Juniper" for product "Junos" and version "15.1x49"
d30
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d20
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d21
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d25
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d30
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d32
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d33
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d34
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d60
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d61
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d62
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1x53
Search vendor "Juniper" for product "Junos" and version "15.1x53"
d63
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
-
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
r1
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
r2
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
r3
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
r4
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
r8
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1
Search vendor "Juniper" for product "Junos" and version "14.1"
r9
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r1
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r2
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r3
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r4
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r5
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r7
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.2
Search vendor "Juniper" for product "Junos" and version "14.2"
r8
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
r1
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
15.1
Search vendor "Juniper" for product "Junos" and version "15.1"
r2
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
-
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r1
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r10
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r2
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r3
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r4
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r5
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r6
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r7
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r8
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
12.3
Search vendor "Juniper" for product "Junos" and version "12.3"
r9
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
-
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d10
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d15
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d16
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d25
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d26
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d27
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d35
Affected
Juniper
Search vendor "Juniper"
Junos
Search vendor "Juniper" for product "Junos"
14.1x53
Search vendor "Juniper" for product "Junos" and version "14.1x53"
d50
Affected