9
CVE-2021-31350
- EPSS 0.87%
- Veröffentlicht 19.10.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:28
- Erkennungen
Junos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)
An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root, leading to complete compromise of the targeted system. The issue is caused by the JET service daemon (jsd) process authenticating the user, then passing configuration operations directly to the management daemon (mgd) process, which runs as root. This issue affects Juniper Networks Junos OS: 18.4 versions prior to 18.4R1-S8, 18.4R2-S8, 18.4R3-S8; 19.1 versions prior to 19.1R2-S3, 19.1R3-S5; 19.2 versions prior to 19.2R1-S7, 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S3; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R2-S3, 20.2R3; 20.3 versions prior to 20.3R2-S1, 20.3R3; 20.4 versions prior to 20.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 18.4R1. Juniper Networks Junos OS Evolved: All versions prior to 20.4R2-EVO; 21.1-EVO versions prior to 21.1R2-EVO.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Os Evolved Version 18.3 Update r1
Juniper ≫ Junos Os Evolved Version 19.1 Update r1
Juniper ≫ Junos Os Evolved Version 19.1 Update r2
Juniper ≫ Junos Os Evolved Version 19.2 Update r1
Juniper ≫ Junos Os Evolved Version 19.2 Update r2
Juniper ≫ Junos Os Evolved Version 19.3 Update r1
Juniper ≫ Junos Os Evolved Version 19.3 Update r2
Juniper ≫ Junos Os Evolved Version 19.4 Update r1
Juniper ≫ Junos Os Evolved Version 19.4 Update r1-s1
Juniper ≫ Junos Os Evolved Version 20.1 Update r1
Juniper ≫ Junos Os Evolved Version 20.1 Update r1-s1
Juniper ≫ Junos Os Evolved Version 20.1 Update r2
Juniper ≫ Junos Os Evolved Version 20.1 Update r2-s1
Juniper ≫ Junos Os Evolved Version 20.1 Update r2-s2
Juniper ≫ Junos Os Evolved Version 20.2 Update r1
Juniper ≫ Junos Os Evolved Version 20.2 Update r1-s1
Juniper ≫ Junos Os Evolved Version 20.2 Update r2
Juniper ≫ Junos Os Evolved Version 20.3 Update r1
Juniper ≫ Junos Os Evolved Version 20.3 Update r1-s1
Juniper ≫ Junos Os Evolved Version 20.3 Update r2
Juniper ≫ Junos Os Evolved Version 20.4 Update r1
Juniper ≫ Junos Os Evolved Version 21.1
Juniper ≫ Junos Os Evolved Version 21.1 Update r1-s1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.87% | 0.557 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
| Juniper | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.