CVE-2025-21590
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/03/2025
Last modified:
14/03/2025
Description
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device.<br />
<br />
A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device.<br />
This issue is not exploitable from the Junos CLI.<br />
This issue affects Junos OS: <br />
<br />
<br />
<br />
* All versions before 21.2R3-S9,<br />
* 21.4 versions before 21.4R3-S10, <br />
* 22.2 versions before 22.2R3-S6, <br />
* 22.4 versions before 22.4R3-S6, <br />
* 23.2 versions before 23.2R2-S3, <br />
* 23.4 versions before 23.4R2-S4,<br />
* 24.2 versions before 24.2R1-S2, 24.2R2.
Impact
Base Score 4.0
6.70
Severity 4.0
MEDIUM
Base Score 3.x
4.40
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:juniper:junos:*:-:*:*:*:*:*:* | 21.2 (including) | |
cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r2-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r2-s2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s3:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s4:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s6:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:21.2:r3-s7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page