On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://kb.juniper.net/JSA10770 | mitigation vendor advisory |
http://www.securityfocus.com/bid/98772 | vdb entry third party advisory |