CVE-2023-44201Incorrect Permission Assignment in Networks Junos OS

Severity
5.5MEDIUMNVD
CNA5.0
EPSS
0.0%
top 88.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13

Description

An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker to read configuration changes without having the permissions. When a user with the respective permissions commits a configuration change, a specific file is created. That file is readable even by users with no permissions to access the configuration. This can lead to privilege escalation as the user can read the passwor

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5juniper_networks/junos_os_evolved21.1-EVO21.1R3-S2-EVO+4
CVEListV5juniper_networks/junos_os21.121.1R3-S4+4
NVDjuniper/junos< 20.4+5

🔴Vulnerability Details

2
GHSA
GHSA-ffxw-phw3-h58r: An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a l2023-10-13
CVEList
Junos OS and Junos OS Evolved: A local attacker can retrieve sensitive information and elevate privileges on the device to an authorized user.2023-10-12

📋Vendor Advisories

1
Juniper
CVE-2023-44201: An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a2023-10-13
CVE-2023-44201 — Incorrect Permission Assignment | cvebase