An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the device to get access to a user account.
When the console cable is disconnected, the logged in user is not logged out. This allows a malicious attacker with physical access to the console to resume a previous session and possibly gain administrative privileges.
This issue affects Junos OS Evolved:
The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Junos_os_evolved | Juniper | 23.2-r2 (including) | 23.2-r2 (including) |
Junos_os_evolved | Juniper | 23.4-r1 (including) | 23.4-r1 (including) |
Junos_os_evolved | Juniper | 23.4-r1-s1 (including) | 23.4-r1-s1 (including) |
Junos_os_evolved | Juniper | 23.4-r1-s2 (including) | 23.4-r1-s2 (including) |