CVE Database
/

CVE-2018-0024

Back to search

CVE-2018-0024

Published: Jul 11, 2018

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

7.8

HIGH

Description

An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.

VendorProductVersions

Juniper Networks

Junos OS

affected
12.1X46 - < 12.1X46-D45
affected
12.3X48 - < 12.3X48-D20
affected
15.1X49 - < 15.1X49-D20

Juniper Networks

Junos OS

affected
12.3 - < 12.3R11

Juniper Networks

Junos OS

affected
14.1X53 - < 14.1X53-D30

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

1041314
vdb-entry
x_refsource_SECTRACK
104718
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now