Multiple instances of Improper Neutralization of Special Elements vulnerabilities exist in Juniper Networks Junos OS Evolved commands, which allow a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users who execute specific CLI commands with a crafted set of parameters to escalate their privileges to root on shell level.Note that these issues are similar to but different from CVE-2021-31356.This issue affects Junos OS Evolved:
Security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during external security research.
The following software releases have been updated to resolve this specific issue: 20.4R3-S7-EVO, 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R2-EVO, 23.2R1-EVO, and all subsequent releases.
This issue is being tracked as 1693858, 1696780, 1696784, 1698062 and 1696781 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue.
To reduce the risk of exploitation limit access to the system for trusted administrators only.
2024-07-10: Initial Publication 2024-09-13: Minor formatting change to CVSS field