cbcvebase.
CVE-2023-44187
published 2023-10-11

CVE-2023-44187: An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell access to…

PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.5th percentile
An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell access to view passwords supplied on the CLI command-line. These credentials can then be used to provide unauthorized access to the remote system.

This issue affects Juniper Networks Junos OS Evolved:
* All versions prior to 20.4R3-S7-EVO;
* 21.1 versions 21.1R1-EVO and later;
* 21.2 versions prior to 21.2R3-S5-EVO;
* 21.3 versions prior to 21.3R3-S4-EVO;
* 21.4 versions prior to 21.4R3-S4-EVO;
* 22.1 versions prior to 22.1R3-S2-EVO;
* 22.2 versions prior to 22.2R2-EVO.

Affected

16 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniperjunos_os_evolved< 20.420.4
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniper_networksjunos_os_evolved< 20.4R3-S7-EVO20.4R3-S7-EVO
juniper_networksjunos_os_evolved>= 21.1R1 < 21.1*21.1*
juniper_networksjunos_os_evolved>= 21.2 < 21.2R3-S5-EVO21.2R3-S5-EVO
juniper_networksjunos_os_evolved>= 21.3 < 21.3R3-S4-EVO21.3R3-S4-EVO
juniper_networksjunos_os_evolved>= 21.4 < 21.4R3-S4-EVO21.4R3-S4-EVO
juniper_networksjunos_os_evolved>= 22.1 < 22.1R3-S2-EVO22.1R3-S2-EVO
juniper_networksjunos_os_evolved>= 22.2 < 22.2R2-EVO22.2R2-EVO
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.