CVE-2017-10615
A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to potentially execute arbitrary code or crash daemons such as telnetd or sshd that make use of PAM. Affected Juniper Networks Junos OS releases are: 14.1 from 14.1R5 prior to 14.1R8-S4, 14.1R9; 14.1X53 prior to 14.1X53-D50 on EX and QFX series; 14.2 from 14.2R3 prior to 14.2R7-S8, 14.2R8; No other Junos OS releases are affected by this issue. No other Juniper Networks products are affected by this issue.
Published:Oct 13, 2017
Last Modified:Apr 20, 2025
EPS:Oct 13, 2017
EPSS Score:0.01716
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Juniper
Product
Ex3200
Juniper
Ex3200
Vendor
Juniper
Product
Ex3300
Juniper
Ex3300
Vendor
Juniper
Product
Ex3300-vc
Juniper
Ex3300-vc
Vendor
Juniper
Product
Ex4200
Juniper
Ex4200
Vendor
Juniper
Product
Ex4200-vc
Juniper
Ex4200-vc
Vendor
Juniper
Product
Ex4300
Juniper
Ex4300
Vendor
Juniper
Product
Ex4300-vc
Juniper
Ex4300-vc
Vendor
Juniper
Product
Ex4500
Juniper
Ex4500
Vendor
Juniper
Product
Ex4500-vc
Juniper
Ex4500-vc
Vendor
Juniper
Product
Ex4550
Juniper
Ex4550
Vendor
Juniper
Product
Ex4550-vc
Juniper
Ex4550-vc
Vendor
Juniper
Product
Ex4600
Juniper
Ex4600
Vendor
Juniper
Product
Ex4600-vc
Juniper
Ex4600-vc
Vendor
Juniper
Product
Ex6200
Juniper
Ex6200
Vendor
Juniper
Product
Ex8200
Juniper
Ex8200
Vendor
Juniper
Product
Ex8200-vc
Juniper
Ex8200-vc
Vendor
Juniper
Product
Junos
Juniper
Junos
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
