Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
References
Link | Resource |
---|---|
https://kb.juniper.net/JSA10872 | Vendor Advisory |
Configurations
Information
Published : 2018-07-11 11:29
Updated : 2019-10-09 16:31
NVD link : CVE-2018-0040
Mitre link : CVE-2018-0040
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
juniper
- contrail_service_orchestration