CVE Feed

    Dashboard / CVE / CVE-2019-0062

    CVE-2019-0062

    A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the device. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15 on EX Series; 12.3X48 versions prior to 12.3X48-D85 on SRX Series; 14.1X53 versions prior to 14.1X53-D51; 15.1 versions prior to 15.1F6-S13, 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D180 on SRX Series; 15.1X53 versions prior to 15.1X53-D238; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R3-S1; 17.2 versions prior to 17.2R2-S8, 17.2R3-S3; 17.3 versions prior to 17.3R3-S5; 17.4 versions prior to 17.4R2-S8, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3; 18.3 versions prior to 18.3R3; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R1-S2, 19.1R2.

    Published:Oct 9, 2019
    Last Modified:Nov 21, 2024
    EPS:Oct 9, 2019
    EPSS Score:0.00357
    CVSS Score:7.5

    Affected Products

    Vendor
    Juniper
    Product
    Csrx
    Vendor
    Juniper
    Product
    Ex2200
    Vendor
    Juniper
    Product
    Ex2200-c
    Vendor
    Juniper
    Product
    Ex2300
    Vendor
    Juniper
    Product
    Ex2300-c
    Vendor
    Juniper
    Product
    Ex3200
    Vendor
    Juniper
    Product
    Ex3300
    Vendor
    Juniper
    Product
    Ex3400
    Vendor
    Juniper
    Product
    Ex4200
    Vendor
    Juniper
    Product
    Ex4300
    Vendor
    Juniper
    Product
    Ex4500
    Vendor
    Juniper
    Product
    Ex4550
    Vendor
    Juniper
    Product
    Ex4600
    Vendor
    Juniper
    Product
    Ex4650
    Vendor
    Juniper
    Product
    Ex6210
    Vendor
    Juniper
    Product
    Ex8208
    Vendor
    Juniper
    Product
    Ex8216
    Vendor
    Juniper
    Product
    Ex9204
    Vendor
    Juniper
    Product
    Ex9208
    Vendor
    Juniper
    Product
    Ex9214
    Vendor
    Juniper
    Product
    Ex9251
    Vendor
    Juniper
    Product
    Ex9253
    Vendor
    Juniper
    Product
    Junos
    Vendor
    Juniper
    Product
    Srx100
    Vendor
    Juniper
    Product
    Srx110
    Vendor
    Juniper
    Product
    Srx1400
    Vendor
    Juniper
    Product
    Srx1500
    Vendor
    Juniper
    Product
    Srx210
    Vendor
    Juniper
    Product
    Srx220
    Vendor
    Juniper
    Product
    Srx240
    Vendor
    Juniper
    Product
    Srx300
    Vendor
    Juniper
    Product
    Srx320
    Vendor
    Juniper
    Product
    Srx340
    Vendor
    Juniper
    Product
    Srx3400
    Vendor
    Juniper
    Product
    Srx345
    Vendor
    Juniper
    Product
    Srx3600
    Vendor
    Juniper
    Product
    Srx4100
    Vendor
    Juniper
    Product
    Srx4200
    Vendor
    Juniper
    Product
    Srx4600
    Vendor
    Juniper
    Product
    Srx5400
    Vendor
    Juniper
    Product
    Srx550
    Vendor
    Juniper
    Product
    Srx550 Hm
    Vendor
    Juniper
    Product
    Srx5600
    Vendor
    Juniper
    Product
    Srx5800
    Vendor
    Juniper
    Product
    Srx650
    Vendor
    Juniper
    Product
    Vsrx

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High