CVE-2023-44201 — Incorrect Permission Assignment in Networks Junos OS
Severity
5.5MEDIUMNVD
CNA5.0
EPSS
0.0%
top 88.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Description
An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker to read configuration changes without having the permissions.
When a user with the respective permissions commits a configuration change, a specific file is created. That file is readable even by users with no permissions to access the configuration. This can lead to privilege escalation as the user can read the passwor…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
2GHSA▶
GHSA-ffxw-phw3-h58r: An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a l↗2023-10-13
CVEList▶
Junos OS and Junos OS Evolved: A local attacker can retrieve sensitive information and elevate privileges on the device to an authorized user.↗2023-10-12
📋Vendor Advisories
1Juniper▶
CVE-2023-44201:
An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a↗2023-10-13