CVE-2013-6618 EXPLOIT
9.0
HIGH · CVSS 2.0 · EPSS 10.6% (pctl 96)
Patch early
A public exploit exists.
Description
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.
Scoring
| CVSS | 9.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
| EPSS | 10.61% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-11-05 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| juniper | junos |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Juniper Junos J-Web - Privilege Escalation | 2013-11-12 |
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10560
- http://secunia.com/advisories/54731
- http://www.exploit-db.com/exploits/29544
- http://www.securityfocus.com/bid/62305
- http://www.securitytracker.com/id/1029016
- http://www.senseofsecurity.com.au/advisories/SOS-13-003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87011
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10560
- http://secunia.com/advisories/54731
- http://www.exploit-db.com/exploits/29544
- http://www.securityfocus.com/bid/62305
- http://www.securitytracker.com/id/1029016
- http://www.senseofsecurity.com.au/advisories/SOS-13-003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87011
→ the Explorer · watch your stack · NVD