CVE-2008-1181 describes a full path disclosure vulnerability in Juniper Networks Secure Access 2000 version 5.5 R1 (build 11711). Remote attackers can exploit this by directly requesting remediate.cgi without specific parameters, causing an "Execute failed" error message that reveals the server's file path. This vulnerability has a CVSS score of 5.0 (medium severity) due to its network-based attack vector, low complexity, and impact limited to information disclosure. While not actively exploited in the wild or on the KEV catalog, public exploit code exists on ExploitDB, and it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5CPE matchmatch criteria | cpe:2.3:a:juniper:secure_access_2000:5.5:r1:build_11711:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.