Security Advisory

CVE-2017-10616

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-13 17:00:00
Last updated 2024-09-17 04:19:11
Assigner juniper
CVSS score 5.3
State PUBLISHED

Description

The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).