CVE-2021-0260

HIGH

Juniper Networks Junos OS <17.3R3-S9 - Info Disclosure

Title source: llm
STIX 2.1

Description

An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to an Unauthorized Control Sphere, or write actions to OIDs that support write operations, against the device without authentication. This issue affects: Juniper Networks Junos OS: 17.2 version 17.2R1 and later versions; 17.3 versions prior to 17.3R3-S9; 17.4 versions prior to 17.4R2-S12, 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S6, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 17.2R1.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://kb.juniper.net/JSA11151

Scores

CVSS v3 7.3
EPSS 0.0067
EPSS Percentile 71.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-285 CWE-497
Status published
Products (3)
juniper/junos 17.2 r1 (18 CPE variants)
juniper/junos 17.3 (21 CPE variants)
juniper/junos 17.4 (11 CPE variants)
Published Apr 22, 2021
Tracked Since Feb 18, 2026