← Vulnerability feed

Vulnerability record · CVE-2016-1265 · published 13 October 2017

CVE-2016-1265: Juniper junos space information exposure vulnerability

Juniper · Junos Space

A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.

9.8 CVSS 3.0 Critical EPSS 2.3% · top 17.4% CWE-200 · Information exposureCWE-255 · CWE-255
9.8CVSS 3.0 base score, v2 7.5
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://kb.juniper.net/JSA10727 Vendor Advisory
https://kb.juniper.net/JSA10727 Vendor Advisory

Track CVE-2016-1265 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-3412Juniper junos space vulnerabilityUnspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary command…EPSS 4.7%10.0CVE-2014-2421Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect con…EPSS 6.6%10.0CVE-2014-0456Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…EPSS 6.6%10.0CVE-2014-0457Oracle jrockit vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attack…EPSS 6.6%10.0CVE-2014-0429Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers…EPSS 7.3%9.8CVE-2014-3413Juniper junos space hard-coded credentials vulnerabilityThe MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers …EPSS 2.1%9.8CVE-2017-10622Juniper junos space improper authentication vulnerabilityAn authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based a…EPSS 5.4%9.8CVE-2016-4926Juniper junos space improper authentication vulnerabilityInsufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2016-1265), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.