PT-2019-3482 · Juniper Networks · Junos
Published
2019-10-09
·
Updated
2020-08-24
·
CVE-2019-0058
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions prior to 12.3X48-D80 on SRX Series.
Description
A vulnerability in the Veriexec subsystem of Juniper Networks Junos OS allows an attacker to fully compromise the host system. A local authenticated user can elevate privileges to gain full control of the system even if they are specifically denied access to perform certain actions. This issue is related to inadequate access control in the Veriexec subsystem.
Recommendations
For Juniper Networks Junos OS versions prior to 12.3X48-D80 on SRX Series, update to version 12.3X48-D80 or later to resolve the issue. As a temporary workaround, consider restricting access to the Veriexec subsystem to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos