SB2021011420 - Privilege escalation in Juniper Junos OS
Published: January 14, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS Command Injection (CVE-ID: CVE-2021-0219)
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in install package validation subsystem. A local user can abuse the request system software add validate-on-host CLI command and execute arbitrary OS commands with root privileges.
Remediation
Install update from vendor's website.