Path traversal in Juniper Junos OS - CVE-2019-0074
Published: October 11, 2019
Juniper Junos OS
Detailed vulnerability description
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local authenticated user can send a specially crafted HTTP request and read arbitrary files on the system.
Note: This vulnerability affects only Junos OS on NFX150 Series, QFX10K Series, EX9200 Series, MX Series and PTX Series with Next-Generation Routing Engine (NG-RE) and vmhost.