QID 43823
Date Published: 2021-04-01
QID 43823: Juniper Junos Multiple Local Privilege Escalation Vulnerabilities (JSA11114)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
Multiple local privilege escalation vulnerabilities in Juniper Networks Junos OS have been reported due to the setuid bit being enabled on multiple binaries.
Affected releases are Junos OS:
all versions prior to 15.1R7-S9;
17.3 versions prior to 17.3R3-S11;
17.4 versions prior to 17.4R2-S12, 17.4R3-S3;
18.1 versions prior to 18.1R3-S11;
18.2 versions prior to 18.2R3-S6;
18.3 versions prior to 18.3R3-S4;
18.4 versions prior to 18.4R2-S7, 18.4R3-S6;
19.1 versions prior to 19.1R2-S2, 19.1R3-S4;
19.2 versions prior to 19.2R1-S6, 19.2R3-S1;
19.3 versions prior to 19.3R3-S1;
19.4 versions prior to 19.4R2-S2, 19.4R3-S1;
20.1 versions prior to 20.1R1-S4, 20.1R2;
20.2 versions prior to 20.2R2.
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
This vulnerability could be exploited to gain access to sensitive information also use this vulnerability to change contents or configuration on the system. Additionally this vulnerability can also be used to cause a denial of service in the form of interruptions in resource availability.
The following software releases have been updated to resolve these specific issues:
Junos OS 15.1R7-S9*, 17.3R3-S11*, 17.4R2-S12, 17.4R3-S3, 18.1R3-S11, 18.2R3-S6, 18.3R3-S4, 18.4R2-S7, 18.4R3-S6, 19.1R2-S2, 19.1R3-S4, 19.2R1-S6, 19.2R3-S1, 19.3R3-S1, 19.4R2-S2, 19.4R3-S1, 20.1R1-S4, 20.1R2, 20.2R2, 20.3R1, and all subsequent releases.
For more information please visit JSA11114.
CVEs related to QID 43823
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA11114 |
|