cbcvebase.
CVE-2024-39544
published 2024-10-11

CVE-2024-39544: An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker…

PriorityP424medium5CVSS 3.1
AVLACLPRLUIRSUCHINAN
EPSS
0.20%
9.6th percentile
An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker to view NETCONF traceoptions files, representing an exposure of sensitive information. On all Junos OS Evolved platforms, when NETCONF traceoptions are configured, NETCONF traceoptions files get created with an incorrect group permission, which allows a low-privileged user can access sensitive information compromising the confidentiality of the system. Junos OS Evolved: * All versions before 20.4R3-S9-EVO, * 21.2-EVO before 21.2R3-S7-EVO, * 21.4-EVO before 21.4R3-S5-EVO, * 22.1-EVO before 22.1R3-S5-EVO, * 22.2-EVO before 22.2R3-S3-EVO, * 22.3-EVO before 22.3R3-EVO, 22.3R3-S2-EVO, * 22.4-EVO before 22.4R3-EVO, * 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO.

Affected

18 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniperjunos_os_evolved< 20.420.4
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniper_networksjunos_os_evolved< 20.4R3-S9-EVO20.4R3-S9-EVO
juniper_networksjunos_os_evolved>= 21.2-EVO < 21.2R3-S7-EVO21.2R3-S7-EVO
juniper_networksjunos_os_evolved>= 21.4-EVO < 21.4R3-S5-EVO21.4R3-S5-EVO
juniper_networksjunos_os_evolved>= 22.1-EVO < 22.1R3-S5-EVO22.1R3-S5-EVO
juniper_networksjunos_os_evolved>= 22.2-EVO < 22.2R3-S3-EVO22.2R3-S3-EVO
juniper_networksjunos_os_evolved>= 22.3-EVO < 22.3R3-S2-EVO22.3R3-S2-EVO
juniper_networksjunos_os_evolved>= 22.4-EVO < 22.4R3-EVO22.4R3-EVO
juniper_networksjunos_os_evolved>= 23.2-EVO < 23.2R1-S2-EVO, 23.2R2-EVO23.2R1-S2-EVO, 23.2R2-EVO

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.