CVSS: v3.1: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
An OS Command Injection vulnerability in OpenSSH, used by Juniper Networks Junos Space, might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations.This issue affects all versions of Junos Space before 24.1R1 Patch V2.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.This issue was discovered by a third-party upstream provider.
The following software releases have been updated to resolve this specific issue: Junos Space 24.1R1 Patch V2, and all subsequent releases.
This issue is being tracked as 1796912 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Limit access to the device only from trusted hosts and administrators.Avoid referencing user names or host names containing shell metacharacters.
2024-10-09: Initial Publication