GPU VulnDB

Database/Firmware, BMC & network fabric

Junos OS Evolved: OS command injection in the CLI lets a low-privileged operator escalate

CVSS 4.8CVE-2025-60006Firmware, BMC & network fabriccurated

Impact

Several Junos OS Evolved CLI commands pass their options through unhardened scripts, so a user with CLI access can inject shell commands and perform operations their assigned permissions forbid. On datacenter switches and routers this collapses the read-only-operator boundary: a NOC account intended only to view state can modify configuration or reach the underlying shell on a device carrying tenant and storage traffic. Juniper rates confidentiality, integrity and availability impact as low each with a local vector, which fits a privilege-boundary bypass inside the device rather than remote takeover. Affects Junos OS Evolved 24.2 before 24.2R2-S2-EVO and 24.4 before 24.4R2-EVO; releases earlier than 24.2R1-EVO are not affected.

Who can reach it

Local CLI access to the device with low privileges - an authenticated operator or limited-role account. Authentication is required; no unauthenticated network path.

What to do

Upgrade to Junos OS Evolved 24.2R2-S2-EVO, 24.4R2-EVO or later per Juniper JSA103163. A Junos Evolved upgrade reboots the routing engine, so schedule per-device against fabric redundancy. Interim mitigation is access control rather than configuration: restrict CLI access to trusted accounts and tighten who holds any login class on these devices, since the flaw is in how permitted commands are processed.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.