CVE-2017-2349 Details
Description
A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access to the device to execute shell commands and elevate privileges. Affected releases are Juniper Networks Junos OS 12.1X44 prior to 12.1X44-D60; 12.1X46 prior to 12.1X46-D50; 12.1X47 prior to 12.1X47-D30, 12.1X47-D35; 12.3X48 prior to 12.3X48-D20, 12.3X48-D30; 15.1X49 prior to 15.1X49-D20, 15.1X49-D30.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA10801 | CVE | Vendor Advisory |
| http://www.securitytracker.com/id/1038898 | CVE | Third Party AdvisoryVDB Entry |
| https://kb.juniper.net/JSA10801 | [email protected] | Vendor Advisory |
| http://www.securitytracker.com/id/1038898 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 12.1x44 12.1x44 d10 12.1x44 d15 12.1x44 d20 12.1x44 d25 12.1x44 d30 12.1x44 d35 12.1x44 d40 12.1x44 d45 12.1x44 d50 12.1x44 d55 12.1x46 12.1x46 d10 12.1x46 d15 12.1x46 d20 12.1x46 d25 12.1x46 d30 12.1x46 d35 12.1x46 d40 12.1x46 d45 12.1x46 d50 12.1x46 d55 12.1x47 12.1x47 d10 12.1x47 d15 12.1x47 d20 12.1x47 d25 12.1x47 d35 12.3x48 12.3x48 d10 12.3x48 d15 12.3x48 d30 15.1x49 d10 15.1x49 d15 15.1x49 d30 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jul 26, 2017 | Initial Analysis | [email protected] |
| Jul 18, 2017 | CVE Modified | [email protected] |
| Jul 17, 2017 | CVE Modified | [email protected] |