CVE-2018-0024
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
11/07/2018
Last modified:
09/10/2019
Description
An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:juniper:junos:12.1x46:*:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d10:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d15:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d20:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d25:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d30:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d35:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:12.1x46:d40:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx110:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx1400:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx210:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx220:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:juniper:srx240:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page