Back to Database
Status published
High
CVE-2017-2306
On Juniper Networks Junos Space versions prior to 16.1R1, due...
Vulnerability Description
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2306
Credits & Attribution
No credits recorded in the NVD database.
More from Juniper Networks
View All →CVE-2025-6549
Junos OS: SRX Series: J-Web can be exposed on additional interfaces
Medium
6.9
CVE-2025-60011
Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap
Medium
6.9
CVE-2025-60010
Junos OS and Junos OS Evolved: Device allows login for user with expired password
Medium
5.3
CVE-2025-60009
Junos Space: CLI Configlet page is vulnerable to reflected cross-site script injection
Medium
5.1
CVE-2025-60007
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash
Medium
6.8
Affected Vendor
Juniper Networks
View all reports →Affected Software
Junos Space
Vulnerable Versions:
versions prior to 16.1R1
Timeline
Official Publish:
May 30th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.