Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0864 | Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services. |
Fixes
Solution
This issue is fixed in Contrail Service Orchestration 4.0.0 and subsequent releases.
Workaround
Limit access to the CSO environment to only trusted networks and hosts.
References
| Link | Providers |
|---|---|
| https://kb.juniper.net/JSA10872 |
|
History
No history.
Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2024-09-16T17:57:49.268Z
Reserved: 2017-11-16T00:00:00
Link: CVE-2018-0040
No data.
Status : Modified
Published: 2018-07-11T18:29:00.917
Modified: 2024-11-21T03:37:24.690
Link: CVE-2018-0040
No data.
OpenCVE Enrichment
No data.
EUVD