CVE-2024-39546
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/07/2024
Last modified:
08/08/2025
Description
A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute with root privileges leading to privilege escalation ultimately compromising the system. <br />
<br />
This issue affects Junos OS Evolved: <br />
<br />
<br />
<br />
* All versions prior to 21.2R3-S8-EVO, <br />
* 21.4 versions prior to 21.4R3-S6-EVO, <br />
* 22.1 versions prior to 22.1R3-S5-EVO, <br />
* 22.2 versions prior to 22.2R3-S3-EVO, <br />
* 22.3 versions prior to 22.3R3-S3-EVO, <br />
* 22.4 versions prior to 22.4R3-EVO, <br />
* 23.2 versions prior to 23.2R2-EVO.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
7.30
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:juniper:junos_os_evolved:18.3:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.1:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.1:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.2:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.2:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.3:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.3:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r1-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r2-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:19.4:r2-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:20.1:-:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:20.1:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:20.1:r1-s1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



