Back

CVE-2017-2320

CRITICAL

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.

Published: Apr 24, 2017 Modified: Jun 17, 2026
CWE-200

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
juniper northstar_controller *

GitHub Security Advisory GHSA-jw9m-g475-84fv

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0...

References (4)

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 1.86%

Top 23% most likely to be exploited

Threat Score 40.6 / 100

Data Sources

NVD EPSS GitHub