Contrail Service Orchestration: Hardcoded credentials for Grafana service
Vulnerability Description
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-0039
Credits & Attribution
No credits recorded in the NVD database.
References
More from Juniper Networks
View All →Affected Vendor
Juniper Networks
View all reports →