Back to Database
Status published
Critical
CVE-2018-0040
Contrail Service Orchestration: hardcoded cryptographic certificates and keys
Vulnerability Description
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-0040
Credits & Attribution
No credits recorded in the NVD database.
References
More from Juniper Networks
View All →CVE-2025-6549
Junos OS: SRX Series: J-Web can be exposed on additional interfaces
Medium
6.9
CVE-2025-60011
Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap
Medium
6.9
CVE-2025-60010
Junos OS and Junos OS Evolved: Device allows login for user with expired password
Medium
5.3
CVE-2025-60009
Junos Space: CLI Configlet page is vulnerable to reflected cross-site script injection
Medium
5.1
CVE-2025-60007
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash
Medium
6.8
Affected Vendor
Juniper Networks
View all reports →Affected Software
Contrail Service Orchestration
Vulnerable Versions:
unspecified
Timeline
Official Publish:
July 11th, 2018
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H