Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2018-0024— Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root

Quick assessment

Affected
Juniper Networks Junos OS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Juniper Junos OS是美国瞻博网络(Juniper Networks)公司的一套专用于该公司的硬件系统的网络操作系统。该操作系统提供了安全编程接口和Junos SDK。 Juniper Junos OS中的shell会话存在安全漏洞,该漏洞源于程序没有正确的管理权限。攻击者可利用该漏洞完全控制系统。以下版本受到影响:Juniper Junos OS 12.1X46版本(在SRX系列平台上),12.3版本(在SRX系列平台上),12.3X48版本(在EX系列上),14.1X53版本(在EX220

AI Predicted 8.8 Difficulty: Easy EPSS 0.38% · P29
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-0024

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root
Source: CVE Program / CVE List V5
Vulnerability Description
An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Juniper Junos OS 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Juniper Junos OS是美国瞻博网络(Juniper Networks)公司的一套专用于该公司的硬件系统的网络操作系统。该操作系统提供了安全编程接口和Junos SDK。 Juniper Junos OS中的shell会话存在安全漏洞,该漏洞源于程序没有正确的管理权限。攻击者可利用该漏洞完全控制系统。以下版本受到影响:Juniper Junos OS 12.1X46版本(在SRX系列平台上),12.3版本(在SRX系列平台上),12.3X48版本(在EX系列上),14.1X53版本(在EX220
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Juniper Networks Junos OS 12.1X46 ~ 12.1X46-D45 -
Juniper Networks Junos OS 12.3 ~ 12.3R11 -
Juniper Networks Junos OS 14.1X53 ~ 14.1X53-D30 -

II. Public POCs for CVE-2018-0024

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0024

请登录查看更多情报信息。

Vendor Advisories for CVE-2018-0024 (2)

Same Patch Batch · Juniper Networks · 2018-07-11 · 14 CVEs total

CVE-2018-0025 Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through
CVE-2018-0026 Junos OS: Stateless IP firewall filter rules stop working as expected after reboot or upgr
CVE-2018-0027 Junos OS: Receipt of malformed RSVP packet may lead to RPD denial of service
CVE-2018-0029 Junos OS: Kernel crash (vmcore) during broadcast storm after enabling 'monitor traffic int
CVE-2018-0030 Junos OS: MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) and PTX1K: Line card may crash upon receipt
CVE-2018-0031 Junos OS: Receipt of specially crafted UDP packets over MPLS may bypass stateless IP firew
CVE-2018-0032 Junos OS: RPD crash when receiving a crafted BGP UPDATE
CVE-2018-0034 Junos OS: A malicious crafted IPv6 DHCP packet may cause the JDHCPD daemon to core
CVE-2018-0035 Junos OS: QFX5200 and QFX10002: Unintended ONIE partition was shipped with certain Junos O
CVE-2018-0037 Junos OS: RPD daemon crashes due to receipt of crafted BGP NOTIFICATION messages
CVE-2018-0039 Contrail Service Orchestration: Hardcoded credentials for Grafana service
CVE-2018-0040 Contrail Service Orchestration: hardcoded cryptographic certificates and keys
CVE-2018-0041 Contrail Service Orchestration: Hardcoded credentials for Keystone service.

IV. Related Vulnerabilities

V. Comments for CVE-2018-0024

No comments yet


Leave a comment