Product Affected

This issue affects all versions of Junos OS.
Medium

Problem

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device.

A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device.
This issue is not exploitable from the Junos CLI.

 

This issue affects Junos OS: 

  • All versions before 21.2R3-S9,
  • 21.4 versions before 21.4R3-S10, 
  • 22.2 versions before 22.2R3-S6, 
  • 22.4 versions before 22.4R3-S6, 
  • 23.2 versions before 23.2R2-S3, 
  • 23.4 versions before 23.4R2-S4,
  • 24.2 versions before 24.2R1-S2, 24.2R2.

 

This issue does not affect Junos OS Evolved.

 

At least one instance of malicious exploitation has been reported to the Juniper SIRT. Customers are encouraged to upgrade to a fixed release as soon as it's available and in the meantime take steps to mitigate this vulnerability.

Solution

The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.

 

Please note that this issue is not fixed for all platforms in the releases specified in the solution section.

For the following products the fix is only available in these releases:

SRX300 Series     21.2R3-S9, 23.4R2-S5*, 24.4R1

SRX550HM         22.2R3-S7*

EX4300 Series     21.4R3-S11*  (except EX4300-48MP which has fixes available as indicated in the solution)

EX4600                21.4R3-S11*  (except EX4650 which has fixes available as indicated in the solution)

ACX1000, ACX1100, ACX2100, ACX2200, ACX4000,

ACX500               21.2R3-S9

MX104                21.2R3-S9

* Future Release

 

This issue is being tracked as 1838460 and 1872010 which are visible on the Customer Support website.

 

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

It is strongly recommended to mitigate the risk of exploitation by restricting shell access to trusted users only.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2025-03-12: Initial Publication
2025-03-12: Corrected hotlinks for CVSS assessments

2025-03-14: Rephrased sentences on Amazon involvement to reduce the chance for confusion

2025-04-09: Updated solution section to clarify which platforms are not fixed in all but only in specific releases

2025-04-14: For the products/platforms specifically mentioned in the solution section: Please note that Junos OS version 21.2R3-S9.20, which was made available last week, does not address the issue completely. We'll publish an updated version with the complete fix and update this advisory as soon as possible.

2025-05-06: For the products/platforms specifically mentioned in the solution section: Please note that Junos OS version 21.2R3-S9.21 has been publish with the complete fix.

Related Information

Acknowledgements

Juniper SIRT would like to acknowledge and thank Matteo Memelli from Amazon for responsibly reporting this issue. Note: Amazon found the issue during internal security research and not due to exploitation.