Database/Firmware, BMC & network fabric
Junos OS: missing authentication in command processing gives a privileged local user root on line cards
Impact
A command-processing path on Junos exposes no authentication check, so a user who already holds privileged CLI access on the routing engine can cross into the Linux-based line cards as root. That is an escalation out of the Junos administrative model into the packet-forwarding hardware itself, where an attacker can persist below the level that a Junos configuration audit or software rollback would inspect. On a datacenter fabric these chassis carry aggregation and edge traffic for many tenants, so a compromised line card sits astride traffic that is not attributable to any single tenant. The record describes local privileged access as the precondition, not remote reachability.
Who can reach it
A local attacker who already holds high-privilege access on the Junos device (AV:L, PR:H). No unauthenticated or network-side path is described in the advisory.
What to do
Upgrade Junos OS to 22.4R3-S8, 23.2R2-S6, 23.4R2-S6, 24.2R2-S3, 24.4R2, 25.2R2 or later, per the vendor bulletin. A Junos upgrade takes the chassis out of service, so schedule a maintenance window and drain traffic to the redundant path first; only chassis running the listed Linux-based line cards are affected. In the interim, tighten who holds privileged Junos accounts and review authentication and command logging on these devices, since the precondition is administrative access.
References
Related entries
- IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processorCVE-2026-16832 · IBM Power Systems Firmware (FSP management network protocol)High
- Linux kernel (drivers/infiniband/core): IWARP port-mapper netlink attributes were accepted as plain strings with noCVE-2026-63860 · Linux kernel (drivers/infiniband/core)High
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountCVE-2022-40259 · AMI MegaRACHigh
- Lenovo XClarity Controller (XCC) - API privilege escalation: A read-only XCC user gains elevated privileges throughCVE-2023-0683 · Lenovo XClarity Controller (XCC) - API privilege escalationHigh
- HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting): Cross-site scripting in the iLO web interface across all threeCVE-2023-28083 · HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.