PT-2019-3482 · Juniper Networks · Junos

Published

2019-10-09

·

Updated

2020-08-24

·

CVE-2019-0058

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions prior to 12.3X48-D80 on SRX Series.
Description A vulnerability in the Veriexec subsystem of Juniper Networks Junos OS allows an attacker to fully compromise the host system. A local authenticated user can elevate privileges to gain full control of the system even if they are specifically denied access to perform certain actions. This issue is related to inadequate access control in the Veriexec subsystem.
Recommendations For Juniper Networks Junos OS versions prior to 12.3X48-D80 on SRX Series, update to version 12.3X48-D80 or later to resolve the issue. As a temporary workaround, consider restricting access to the Veriexec subsystem to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03657
CVE-2019-0058

Affected Products

Junos