Database/Firmware, BMC & network fabric
Juniper Junos OS kernel: Improper isolation in the Junos kernel lets a local attacker with shell access inject
CVSS 4.4CVE-2025-21590Firmware, BMC & network fabricKnown exploitedcurated
Impact
Improper isolation in the Junos kernel lets a local attacker with shell access inject arbitrary code — exploited in the wild to implant persistent backdoors on routers
Who can reach it
Local, shell access
What to do
Junos upgrade fleet-wide with routing failover; the in-the-wild usage means affected devices need forensic verification, not just patching
References
Related entries
- Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication modeCVE-2021-3956 · Lenovo XClarity Controller (LDAP mode)Medium
- tpm2-tss (FAPI quote verification): The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATEDCVE-2024-29040 · tpm2-tss (FAPI quote verification)Medium
- Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMICVE-2024-8059 · Lenovo XClarity Controller (XCC) - audit logMedium
- Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local userCVE-2025-31938 · Intel Xeon 6 Scalable processors with Intel TDX (subsystem access control)Medium
- Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashesCVE-2025-54548 · Arista DANZ Monitoring Fabric (debug API exposing the config database)Medium
- Self-encrypting drives in TCG Opal / eDrive modeCVE-2015-7267 · Self-encrypting drives in TCG Opal / eDrive mode - Samsung 850 Pro, Samsung PM851, Seagate ST500LT015, ST500LT025 on…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.