CVE-2018-0039
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-798, CWE-561
- Published
- 2018-07-11
- Last modified
- 2026-03-14
Affected products
- Juniper Networks Contrail Service Orchestration
Weakness type
Related vulnerabilities
- CVE-2026-75940 — A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the...
- CVE-2026-17038 — Use of Hard-coded Credentials in drEryk Gabinet
- CVE-2026-81640 — Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials
- CVE-2026-79731 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79950 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79740 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79738 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...