CVE-2023-28966

An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and directory permissions on certain system files, allowing an attacker with access to these files and folders to inject CLI commands as root. This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S5-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r3-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r3-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r3-s3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.4:r3-s4:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:r2-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.2:r2-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.3:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.3:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:21.3:r1-s1:*:*:*:*:*:*

History

21 Nov 2024, 07:56

Type Values Removed Values Added
References () https://supportportal.juniper.net/JSA70590 - Vendor Advisory () https://supportportal.juniper.net/JSA70590 - Vendor Advisory

Information

Published : 2023-04-17 22:15

Updated : 2024-11-21 07:56


NVD link : CVE-2023-28966

Mitre link : CVE-2023-28966

CVE.ORG link : CVE-2023-28966


JSON object : View

Products Affected

juniper

  • junos_os_evolved
CWE
CWE-276

Incorrect Default Permissions