Vulnerabilities (CVE)

Filtered by vendor Juniper Subscribe
Filtered by product Session And Resource Control
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-31352 1 Juniper 1 Session And Resource Control 2021-10-26 5.0 MEDIUM 5.3 MEDIUM
An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers, which could allow a remote attacker to obtain sensitive information. A remote attacker with read and write access to network data could exploit this vulnerability to display plaintext bits from a block of ciphertext and obtain sensitive information. This issue affects all Juniper Networks SRC Series versions prior to 4.13.0-R6.
CVE-2021-31380 1 Juniper 1 Session And Resource Control 2021-10-25 5.0 MEDIUM 5.3 MEDIUM
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows the attacker to obtain sensitive information.