PT-2019-3593 · Juniper Networks · Junos

Publicado

2019-10-09

·

Atualizado

2020-09-29

·

CVE-2019-0071

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions 18.1R3-S4 on EX2300, EX2300-C, and EX3400 Junos OS versions 18.3R1-S3 on EX2300, EX2300-C, and EX3400
Description The Veriexec subsystem in Junos OS, responsible for ensuring only authorized binaries are executed, fails to initialize due to a flaw. This allows a locally authenticated user with shell access to install untrusted executable images and potentially elevate privileges to gain full control of the system. During the installation of an affected version of Junos OS, error messages related to undefined symbols and authentication errors are logged to the console.
Recommendations For Junos OS versions 18.1R3-S4 on EX2300, EX2300-C, and EX3400: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Junos OS versions 18.3R1-S3 on EX2300, EX2300-C, and EX3400: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03802
CVE-2019-0071

Produtos afetados

Junos