CVE-2024-39546

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/07/2024
Last modified:
08/08/2025

Description

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute with root privileges leading to privilege escalation ultimately compromising the system. <br /> <br /> This issue affects Junos OS Evolved: <br /> <br /> <br /> <br /> * All versions prior to 21.2R3-S8-EVO, <br /> * 21.4 versions prior to  21.4R3-S6-EVO, <br /> * 22.1 versions prior to 22.1R3-S5-EVO, <br /> * 22.2 versions prior to 22.2R3-S3-EVO, <br /> * 22.3 versions prior to 22.3R3-S3-EVO, <br /> * 22.4 versions prior to 22.4R3-EVO, <br /> * 23.2 versions prior to 23.2R2-EVO.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:juniper:junos_os_evolved:18.3:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.1:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.1:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.2:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.2:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.3:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.3:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.4:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.4:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.4:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.4:r2-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:19.4:r2-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.1:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.1:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:20.1:r1-s1:*:*:*:*:*:*