VendorsJunipercontrail_service_orchestrationall versions
Vulnerabilities

Juniper Contrail Service Orchestration

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-0040
Contrail Service Orchestration: hardcoded cryptographic certificates and keys
Published 2018-07-11 · Modified
10.0EPSS 0.014
CVE-2018-0042
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
Published 2018-07-11 · Modified
9.8EPSS 0.011
CVE-2018-0038
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Cassandra.
Published 2018-07-11 · Modified
9.8EPSS 0.011
CVE-2018-0041
Contrail Service Orchestration: Hardcoded credentials for Keystone service.
Published 2018-07-11 · Modified
9.8EPSS 0.011
CVE-2018-0039
Contrail Service Orchestration: Hardcoded credentials for Grafana service
Published 2018-07-11 · Modified
9.8EPSS 0.010
CVE-2022-22189
Contrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authentication
Published 2022-04-14 · Modified
7.8EPSS 0.002
CVE-2022-22152
Contrail Service Orchestration: Tenants able to see other tenants policies via REST API interface
Published 2022-01-19 · Modified
7.7EPSS 0.008