CVE-2017-2343 describes a critical vulnerability in the Integrated User Firewall (UserFW) feature of Juniper Junos OS on SRX Series devices, specifically affecting versions 12.3X48 (prior to D35) and 15.1X49 (prior to D50). This flaw stems from hardcoded credentials within the UserFW services authentication API, which an unauthenticated attacker can exploit remotely to gain complete compromise of SRX Series devices. Successful exploitation can also lead to full administrative control over integrated LDAP and Active Directory servers, potentially exposing user credentials and other critical organizational assets. Despite its critical CVSS score of 9.8, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d20:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d25:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d30:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.