CVE-2024-39527
6.8
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: sirt@juniper.net (Secondary)
Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the file system.
Through the execution of crafted CLI commands, a user with limited permissions (e.g., a low privilege login class user) can access protected files that should not be accessible to the user. These files may contain sensitive information that can be used to cause further impact to the system.
This issue affects Junos OS on SRX Series:
* All versions before 21.4R3-S8,
* 22.2 before 22.2R3-S5,
* 22.3 before 22.3R3-S4,
* 22.4 before 22.4R3-S4,
* 23.2 before 23.2R2-S2,
* 23.4 before 23.4R2.
Affected (60)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 21.4 |
| Running on/with | Platform Versions |
|---|---|
Juniper Srx1500 | All versions |
Juniper Srx1600 | All versions |
Juniper Srx2300 | All versions |
Juniper Srx300 | All versions |
Juniper Srx320 | All versions |
Juniper Srx340 | All versions |
Juniper Srx345 | All versions |
Juniper Srx380 | All versions |
Juniper Srx4100 | All versions |
Juniper Srx4120 | All versions |
Juniper Srx4200 | All versions |
Juniper Srx4300 | All versions |
Juniper Srx4600 | All versions |
Juniper Srx4700 | All versions |
Juniper Srx5400 | All versions |
Juniper Srx5600 | All versions |
Juniper Srx5800 | All versions |
References (1)
Timeline
No history available yet.