peter bassill · operator
$ cve CVE-2013-6618 JSON

CVE-2013-6618 EXPLOIT

9.0
HIGH · CVSS 2.0 · EPSS 10.6% (pctl 96)

Patch early

A public exploit exists.

Description

jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.

Scoring

CVSS9.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS10.61% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2013-11-05
Last modified2026-06-17

Affected (1)

VendorProduct
juniperjunos

Public exploits

SourceTitleDate
exploit-dbJuniper Junos J-Web - Privilege Escalation2013-11-12

References

→ the Explorer  ·  watch your stack  ·  NVD