Hardcoded Credentials in Juniper Networks Contrail Service Orchestration Allow Unauthorized Access to Cassandra

Hardcoded Credentials in Juniper Networks Contrail Service Orchestration Allow Unauthorized Access to Cassandra

CVE-2018-0038 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Cassandra.

Learn more about our Cis Benchmark Audit For Apache Cassandra.