PT-2023-6243 · Juniper Networks · Junos Evolved

Published

2023-10-11

·

Updated

2023-10-19

·

CVE-2023-44187

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Junos OS Evolved versions prior to 20.4R3-S7-EVO Junos OS Evolved version 21.1R1-EVO and later Junos OS Evolved versions prior to 21.2R3-S5-EVO Junos OS Evolved versions prior to 21.3R3-S4-EVO Junos OS Evolved versions prior to 21.4R3-S4-EVO Junos OS Evolved versions prior to 22.1R3-S2-EVO Junos OS Evolved versions prior to 22.2R2-EVO
Description An Exposure of Sensitive Information issue in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell access to view passwords supplied on the CLI command-line. These credentials can then be used to provide unauthorized access to the remote system.
Recommendations For versions prior to 20.4R3-S7-EVO, update to version 20.4R3-S7-EVO or later. For version 21.1R1-EVO and later, update to version 21.2R3-S5-EVO or later. For versions prior to 21.2R3-S5-EVO, update to version 21.2R3-S5-EVO or later. For versions prior to 21.3R3-S4-EVO, update to version 21.3R3-S4-EVO or later. For versions prior to 21.4R3-S4-EVO, update to version 21.4R3-S4-EVO or later. For versions prior to 22.1R3-S2-EVO, update to version 22.1R3-S2-EVO or later. For versions prior to 22.2R2-EVO, update to version 22.2R2-EVO or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-06952
CVE-2023-44187

Affected Products

Junos Evolved