SB2024071551 - Privilege escalation in Junos OS Evolved
Published: July 15, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper physical access control (CVE-ID: CVE-2024-39512)
The vulnerability allows a local non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper physical access control error in the console port control. A local non-authenticated attacker can the device to get access to a user account.
When the console cable is disconnected, the logged in user is not logged out.
This allows a malicious attacker with physical access to the console to resume a previous session and possibly gain administrative privileges.
Remediation
Install update from vendor's website.