CVE-2013-4689
Last modified
CVE-2013-4689 is a vulnerability of currently unknown severity. J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | <= 10.4 |
| Juniper | Junos | 4.0 |
| Juniper | Junos | 4.1 |
| Juniper | Junos | 4.2 |
| Juniper | Junos | 4.3 |
| Juniper | Junos | 4.4 |
| Juniper | Junos | 5.0 |
| Juniper | Junos | 5.1 |
| Juniper | Junos | 5.2 |
| Juniper | Junos | 5.3 |
| Juniper | Junos | 5.4 |
| Juniper | Junos | 5.5 |
| Juniper | Junos | 5.6 |
| Juniper | Junos | 5.7 |
| Juniper | Junos | 6.0 |
| Juniper | Junos | 6.1 |
| Juniper | Junos | 6.2 |
| Juniper | Junos | 6.3 |
| Juniper | Junos | 6.4 |
| Juniper | Junos | 7.0 |
| Juniper | Junos | 7.1 |
| Juniper | Junos | 7.2 |
| Juniper | Junos | 7.3 |
| Juniper | Junos | 7.4 |
| Juniper | Junos | 7.5 |
| Juniper | Junos | 7.6 |
| Juniper | Junos | 8.0 |
| Juniper | Junos | 8.1 |
| Juniper | Junos | 8.2 |
| Juniper | Junos | 8.3 |
| Juniper | Junos | 8.4 |
| Juniper | Junos | 9.0 |
| Juniper | Junos | 9.1 |
| Juniper | Junos | 9.2 |
| Juniper | Junos | 9.4 |
| Juniper | Junos | 9.5 |
| Juniper | Junos | 9.6 |
| Juniper | Junos | 11.4 |
| Juniper | Junos | 12.1 |
| Juniper | Junos | 12.1x44 |
| Juniper | Junos | 12.1x45 |
| Juniper | Junos | 12.2 |
| Juniper | Junos | 12.3 |
| Juniper | Junos | 13.1 |
References
- http://secunia.com/advisories/55166Vendor Advisory
- http://secunia.com/advisories/55166Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4689?
How severe is CVE-2013-4689?
How do I fix CVE-2013-4689?
Are you affected by CVE-2013-4689?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
