CVE-2018-0015
Last modified
CVE-2018-0015 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Agent is executing. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Agent is executing. If the host is executing AppFormix Agent, an attacker may access the debug console and execute Python commands with root privilege. Affected AppFormix releases are: All versions up to and including 2.7.3; 2.11 versions prior to 2.11.3; 2.15 versions prior to 2.15.2. Juniper SIRT is not aware of any malicious exploitation of this vulnerability, however, the issue has been seen in a production network. No other Juniper Networks products or platforms are affected by this issue.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Appformix | <= 2.7.3 |
| Juniper | Appformix | >= 2.11, < 2.11.3 |
| Juniper | Appformix | >= 2.15, < 2.15.2 |
References
- https://kb.juniper.net/JSA10843Vendor Advisory
- https://kb.juniper.net/JSA10843Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0015?
How severe is CVE-2018-0015?
How do I fix CVE-2018-0015?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-0009On Juniper Networks SRX series devices, firewall rules confi…5.4
- CVE-2018-0010A vulnerability in the Juniper Networks Junos Space Security…
- CVE-2018-0011A reflected cross site scripting (XSS) vulnerability in Juno…5.4
- CVE-2018-0012Junos Space is affected by a privilege escalation vulnerabil…7.8
- CVE-2018-0013A local file inclusion vulnerability in Juniper Networks Jun…6.5
- CVE-2018-0014Juniper Networks ScreenOS devices do not pad Ethernet packet…4.3
- CVE-2018-0016Receipt of a specially crafted Connectionless Network Protoc…9.8
- CVE-2018-0017A vulnerability in the Network Address Translation - Protoco…7.5
- CVE-2018-0018On SRX Series devices during compilation of IDP policies, an…7.5
- CVE-2018-0019A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib…5.3
- CVE-2018-0020Junos OS may be impacted by the receipt of a malformed BGP U…7.5
- CVE-2018-0021If all 64 digits of the connectivity association name (CKN) …8.8
Are you affected by CVE-2018-0015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
