An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104718 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041314 | Third Party Advisory VDB Entry |
https://kb.juniper.net/JSA10857 | Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/104718 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041314 | Third Party Advisory VDB Entry |
https://kb.juniper.net/JSA10857 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
21 Nov 2024, 03:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/104718 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1041314 - Third Party Advisory, VDB Entry | |
References | () https://kb.juniper.net/JSA10857 - Mitigation, Vendor Advisory |
Information
Published : 2018-07-11 18:29
Updated : 2024-11-21 03:37
NVD link : CVE-2018-0024
Mitre link : CVE-2018-0024
CVE.ORG link : CVE-2018-0024
JSON object : View
Products Affected
juniper
- srx1400
- srx300
- ex2200\/vc
- ex4550
- srx3600
- srx210
- junos
- ex4300
- srx340
- qfx5100
- srx550
- srx4200
- srx3400
- ex2300
- ex2200
- ex6200
- ex3300\/vc
- ex3300
- ex4550\/vc
- srx5800
- srx345
- ex2300-c
- ex3200
- srx1500
- srx220
- srx650
- ex2200-c
- srx5600
- ex4200
- srx5400
- ex_rps
- ex3400
- ex9200
- srx100
- qfx3500
- ex8200\/vc_\(xre\)
- srx110
- srx320
- srx240
- ex4600
- srx4100
- qfx3600
CWE
CWE-269
Improper Privilege Management