Product Affected

This issue affects all versions of Junos OS Evolved 0, 21.2-EVO, 21.4-EVO, 22.2-EVO, 22.3-EVO, 22.4-EVO. Affected platforms: PTX Series, ACX Series, QFX Series.
High
CVSS 3.1: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVSS 4.0: 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)

Problem

Multiple instances of Improper Neutralization of Special Elements vulnerabilities exist in Juniper Networks Junos OS Evolved commands, which allow a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.

The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users who execute specific CLI commands with a crafted set of parameters to escalate their privileges to root on shell level.

Note that these issues are similar to but different from CVE-2021-31356.

This issue affects Junos OS Evolved:

  • All version before 20.4R3-S7-EVO, 
  • 21.2-EVO versions before 21.2R3-S8-EVO,
  • 21.4-EVO versions before 21.4R3-S7-EVO, 
  • 22.2-EVO versions before 22.2R3-EVO, 
  • 22.3-EVO versions before 22.3R2-EVO,
  • 22.4-EVO versions before 22.4R2-EVO.

 

Security issues resolved include:

CVECVSSSummary
CVE-2024-395207.8An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.
CVE-2024-395217.8An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.
CVE-2024-395227.8An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.
CVE-2024-395237.8An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.
CVE-2024-395247.8An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.

 

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was discovered during external security research.

Solution

The following software releases have been updated to resolve this specific issue: 20.4R3-S7-EVO, 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R2-EVO, 23.2R1-EVO, and all subsequent releases.
 

This issue is being tracked as 1693858169678016967841698062 and 1696781 which are visible on the Customer Support website.
 

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

To reduce the risk of exploitation limit access to the system for trusted administrators only.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2024-07-10: Initial Publication
2024-09-13: Minor formatting change to CVSS field

Related Information