Database/Firmware, BMC & network fabric
Junos OS Evolved: OS command injection in the CLI lets a low-privileged operator escalate
Impact
Several Junos OS Evolved CLI commands pass their options through unhardened scripts, so a user with CLI access can inject shell commands and perform operations their assigned permissions forbid. On datacenter switches and routers this collapses the read-only-operator boundary: a NOC account intended only to view state can modify configuration or reach the underlying shell on a device carrying tenant and storage traffic. Juniper rates confidentiality, integrity and availability impact as low each with a local vector, which fits a privilege-boundary bypass inside the device rather than remote takeover. Affects Junos OS Evolved 24.2 before 24.2R2-S2-EVO and 24.4 before 24.4R2-EVO; releases earlier than 24.2R1-EVO are not affected.
Who can reach it
Local CLI access to the device with low privileges - an authenticated operator or limited-role account. Authentication is required; no unauthenticated network path.
What to do
Upgrade to Junos OS Evolved 24.2R2-S2-EVO, 24.4R2-EVO or later per Juniper JSA103163. A Junos Evolved upgrade reboots the routing engine, so schedule per-device against fabric redundancy. Interim mitigation is access control rather than configuration: restrict CLI access to trusted accounts and tighten who holds any login class on these devices, since the flaw is in how permitted commands are processed.
References
Related entries
- Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a sideCVE-2018-3626 · Intel SGX SDK (Edger8r generated code, side channel)Medium
- AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86CVE-2021-26318 · AMD processors - PREFETCH instruction timing and power side channelMedium
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsCVE-2022-27672 · AMD processors with SMT - speculative execution across SMT mode switchMedium
- Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processorCVE-2022-28693 · Intel processors (return stack buffer alternate prediction)Medium
- AMD processors - power side channel on cache line data changes: An authenticated attacker who can read CPU powerCVE-2023-20583 · AMD processors - power side channel on cache line data changesMedium
- Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them toCVE-2024-56742 · Linux kernel (drivers/vfio/pci/mlx5)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.