CVE-2017-10603

EUVD-2017-2250
An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 15.1X53 prior to 15.1X53-D47, 15.1 prior to 15.1R3. Junos versions prior to 15.1 are not affected. No other Juniper Networks products or platforms are affected by this issue.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
juniperCNA
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1x53:x53
juniperjunos
15.1
juniperjunos
15.1:a1
juniperjunos
15.1:f1
juniperjunos
15.1:f2
juniperjunos
15.1:f2-s1
juniperjunos
15.1:f2-s2
juniperjunos
15.1:f2-s3
juniperjunos
15.1:f2-s4
juniperjunos
15.1:f3
juniperjunos
15.1:f4
juniperjunos
15.1:f6
juniperjunos
15.1:f7
juniperjunos
15.1:r1
juniperjunos
15.1:r2
𝑥
= Vulnerable software versions