PT-2018-8580 · Juniper Networks · Junos

Publicado

2018-07-11

·

Atualizado

2019-10-09

·

CVE-2018-0035

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Junos OS versions 15.1X53-D21 through 15.1X53-D60
Description: The issue allows a superuser to reboot to an unintended additional Open Network Install Environment (ONIE) partition, which wipes out the content of the Junos partition and its configuration. After rebooting, the ONIE partition does not have a root password configured, allowing any user to access the console or SSH as root without a password using an IP address acquired from DHCP.
Recommendations: For Junos OS versions 15.1X53-D21 through 15.1X53-D60, the issue will persist even after upgrading to a higher release via the CLI. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-0035

Produtos afetados

Junos