PT-2023-3072 · Juniper Networks · Junos Evolved
Published
2023-04-12
·
Updated
2023-05-04
·
CVE-2023-28983
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS Evolved versions 21.4R1-EVO through 22.1R1-EVO
Description
The issue is related to an OS Command Injection vulnerability in the gRPC Network Operations Interface (gNOI) server module. This allows an authenticated, low-privileged, network-based attacker to inject shell commands and execute code. The vulnerability can be exploited by a remote attacker, potentially leading to the execution of arbitrary code.
Recommendations
For Juniper Networks Junos OS Evolved versions 21.4R1-EVO through 22.1R1-EVO, update to version 22.1R1-EVO or later to resolve the issue. As a temporary workaround, consider restricting access to the gNOI server module to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Evolved