A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute with root privileges leading to privilege escalation ultimately compromising the system.
This issue affects Junos OS Evolved:
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Junos_os_evolved | Juniper | 18.3-r1 (including) | 18.3-r1 (including) |
Junos_os_evolved | Juniper | 19.1-r1 (including) | 19.1-r1 (including) |
Junos_os_evolved | Juniper | 19.1-r2 (including) | 19.1-r2 (including) |
Junos_os_evolved | Juniper | 19.2-r1 (including) | 19.2-r1 (including) |
Junos_os_evolved | Juniper | 19.2-r2 (including) | 19.2-r2 (including) |
Junos_os_evolved | Juniper | 19.3-r1 (including) | 19.3-r1 (including) |
Junos_os_evolved | Juniper | 19.3-r2 (including) | 19.3-r2 (including) |
Junos_os_evolved | Juniper | 19.4-r1 (including) | 19.4-r1 (including) |
Junos_os_evolved | Juniper | 19.4-r1-s1 (including) | 19.4-r1-s1 (including) |
Junos_os_evolved | Juniper | 19.4-r2 (including) | 19.4-r2 (including) |
Junos_os_evolved | Juniper | 19.4-r2-s1 (including) | 19.4-r2-s1 (including) |
Junos_os_evolved | Juniper | 19.4-r2-s2 (including) | 19.4-r2-s2 (including) |
Junos_os_evolved | Juniper | 20.1 (including) | 20.1 (including) |
Junos_os_evolved | Juniper | 20.1-r1 (including) | 20.1-r1 (including) |
Junos_os_evolved | Juniper | 20.1-r1-s1 (including) | 20.1-r1-s1 (including) |
Junos_os_evolved | Juniper | 20.1-r2 (including) | 20.1-r2 (including) |
Junos_os_evolved | Juniper | 20.1-r2-s1 (including) | 20.1-r2-s1 (including) |
Junos_os_evolved | Juniper | 20.1-r2-s2 (including) | 20.1-r2-s2 (including) |
Junos_os_evolved | Juniper | 20.1-r2-s3 (including) | 20.1-r2-s3 (including) |
Junos_os_evolved | Juniper | 20.1-r2-s4 (including) | 20.1-r2-s4 (including) |
Junos_os_evolved | Juniper | 20.1-r2-s5 (including) | 20.1-r2-s5 (including) |
Junos_os_evolved | Juniper | 20.1-r3 (including) | 20.1-r3 (including) |
Junos_os_evolved | Juniper | 20.2 (including) | 20.2 (including) |
Junos_os_evolved | Juniper | 20.2-r1 (including) | 20.2-r1 (including) |
Junos_os_evolved | Juniper | 20.2-r1-s1 (including) | 20.2-r1-s1 (including) |
Junos_os_evolved | Juniper | 20.2-r2 (including) | 20.2-r2 (including) |
Junos_os_evolved | Juniper | 20.2-r2-s1 (including) | 20.2-r2-s1 (including) |
Junos_os_evolved | Juniper | 20.2-r3 (including) | 20.2-r3 (including) |
Junos_os_evolved | Juniper | 20.3 (including) | 20.3 (including) |
Junos_os_evolved | Juniper | 20.3-r1 (including) | 20.3-r1 (including) |
Junos_os_evolved | Juniper | 20.3-r1-s1 (including) | 20.3-r1-s1 (including) |
Junos_os_evolved | Juniper | 20.3-r1-s2 (including) | 20.3-r1-s2 (including) |
Junos_os_evolved | Juniper | 20.3-r1-s3 (including) | 20.3-r1-s3 (including) |
Junos_os_evolved | Juniper | 20.3-r2 (including) | 20.3-r2 (including) |
Junos_os_evolved | Juniper | 20.4 (including) | 20.4 (including) |
Junos_os_evolved | Juniper | 20.4-r1 (including) | 20.4-r1 (including) |
Junos_os_evolved | Juniper | 20.4-r1-s1 (including) | 20.4-r1-s1 (including) |
Junos_os_evolved | Juniper | 20.4-r1-s2 (including) | 20.4-r1-s2 (including) |
Junos_os_evolved | Juniper | 20.4-r2 (including) | 20.4-r2 (including) |
Junos_os_evolved | Juniper | 20.4-r2-s1 (including) | 20.4-r2-s1 (including) |
Junos_os_evolved | Juniper | 20.4-r2-s2 (including) | 20.4-r2-s2 (including) |
Junos_os_evolved | Juniper | 20.4-r2-s3 (including) | 20.4-r2-s3 (including) |
Junos_os_evolved | Juniper | 20.4-r3 (including) | 20.4-r3 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s1 (including) | 20.4-r3-s1 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s2 (including) | 20.4-r3-s2 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s3 (including) | 20.4-r3-s3 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s4 (including) | 20.4-r3-s4 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s5 (including) | 20.4-r3-s5 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s6 (including) | 20.4-r3-s6 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s7 (including) | 20.4-r3-s7 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s8 (including) | 20.4-r3-s8 (including) |
Junos_os_evolved | Juniper | 20.4-r3-s9 (including) | 20.4-r3-s9 (including) |
Junos_os_evolved | Juniper | 21.1 (including) | 21.1 (including) |
Junos_os_evolved | Juniper | 21.1-r1 (including) | 21.1-r1 (including) |
Junos_os_evolved | Juniper | 21.1-r1-s1 (including) | 21.1-r1-s1 (including) |
Junos_os_evolved | Juniper | 21.1-r2 (including) | 21.1-r2 (including) |
Junos_os_evolved | Juniper | 21.1-r3 (including) | 21.1-r3 (including) |
Junos_os_evolved | Juniper | 21.1-r3-s1 (including) | 21.1-r3-s1 (including) |
Junos_os_evolved | Juniper | 21.1-r3-s2 (including) | 21.1-r3-s2 (including) |
Junos_os_evolved | Juniper | 21.1-r3-s3 (including) | 21.1-r3-s3 (including) |
Junos_os_evolved | Juniper | 21.2 (including) | 21.2 (including) |
Junos_os_evolved | Juniper | 21.2-r1 (including) | 21.2-r1 (including) |
Junos_os_evolved | Juniper | 21.2-r1-s1 (including) | 21.2-r1-s1 (including) |
Junos_os_evolved | Juniper | 21.2-r1-s2 (including) | 21.2-r1-s2 (including) |
Junos_os_evolved | Juniper | 21.2-r2 (including) | 21.2-r2 (including) |
Junos_os_evolved | Juniper | 21.2-r2-s1 (including) | 21.2-r2-s1 (including) |
Junos_os_evolved | Juniper | 21.2-r2-s2 (including) | 21.2-r2-s2 (including) |
Junos_os_evolved | Juniper | 21.2-r3 (including) | 21.2-r3 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s1 (including) | 21.2-r3-s1 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s2 (including) | 21.2-r3-s2 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s3 (including) | 21.2-r3-s3 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s4 (including) | 21.2-r3-s4 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s5 (including) | 21.2-r3-s5 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s6 (including) | 21.2-r3-s6 (including) |
Junos_os_evolved | Juniper | 21.2-r3-s7 (including) | 21.2-r3-s7 (including) |
Junos_os_evolved | Juniper | 21.4 (including) | 21.4 (including) |
Junos_os_evolved | Juniper | 21.4-r1 (including) | 21.4-r1 (including) |
Junos_os_evolved | Juniper | 21.4-r1-s1 (including) | 21.4-r1-s1 (including) |
Junos_os_evolved | Juniper | 21.4-r1-s2 (including) | 21.4-r1-s2 (including) |
Junos_os_evolved | Juniper | 21.4-r2 (including) | 21.4-r2 (including) |
Junos_os_evolved | Juniper | 21.4-r2-s1 (including) | 21.4-r2-s1 (including) |
Junos_os_evolved | Juniper | 21.4-r2-s2 (including) | 21.4-r2-s2 (including) |
Junos_os_evolved | Juniper | 21.4-r3-s1 (including) | 21.4-r3-s1 (including) |
Junos_os_evolved | Juniper | 21.4-r3-s2 (including) | 21.4-r3-s2 (including) |
Junos_os_evolved | Juniper | 21.4-r3-s3 (including) | 21.4-r3-s3 (including) |
Junos_os_evolved | Juniper | 21.4-r3-s4 (including) | 21.4-r3-s4 (including) |
Junos_os_evolved | Juniper | 21.4-r3-s5 (including) | 21.4-r3-s5 (including) |
Junos_os_evolved | Juniper | 22.1 (including) | 22.1 (including) |
Junos_os_evolved | Juniper | 22.1-r1 (including) | 22.1-r1 (including) |
Junos_os_evolved | Juniper | 22.1-r1-s1 (including) | 22.1-r1-s1 (including) |
Junos_os_evolved | Juniper | 22.1-r1-s2 (including) | 22.1-r1-s2 (including) |
Junos_os_evolved | Juniper | 22.1-r2 (including) | 22.1-r2 (including) |
Junos_os_evolved | Juniper | 22.1-r2-s1 (including) | 22.1-r2-s1 (including) |
Junos_os_evolved | Juniper | 22.1-r3-s1 (including) | 22.1-r3-s1 (including) |
Junos_os_evolved | Juniper | 22.1-r3-s2 (including) | 22.1-r3-s2 (including) |
Junos_os_evolved | Juniper | 22.1-r3-s3 (including) | 22.1-r3-s3 (including) |
Junos_os_evolved | Juniper | 22.1-r3-s4 (including) | 22.1-r3-s4 (including) |
Junos_os_evolved | Juniper | 22.2 (including) | 22.2 (including) |
Junos_os_evolved | Juniper | 22.2-r1 (including) | 22.2-r1 (including) |
Junos_os_evolved | Juniper | 22.2-r1-s1 (including) | 22.2-r1-s1 (including) |
Junos_os_evolved | Juniper | 22.2-r1-s2 (including) | 22.2-r1-s2 (including) |
Junos_os_evolved | Juniper | 22.2-r2 (including) | 22.2-r2 (including) |
Junos_os_evolved | Juniper | 22.2-r2-s1 (including) | 22.2-r2-s1 (including) |
Junos_os_evolved | Juniper | 22.2-r2-s2 (including) | 22.2-r2-s2 (including) |
Junos_os_evolved | Juniper | 22.2-r3-s1 (including) | 22.2-r3-s1 (including) |
Junos_os_evolved | Juniper | 22.2-r3-s2 (including) | 22.2-r3-s2 (including) |
Junos_os_evolved | Juniper | 22.3 (including) | 22.3 (including) |
Junos_os_evolved | Juniper | 22.3-r1 (including) | 22.3-r1 (including) |
Junos_os_evolved | Juniper | 22.3-r1-s1 (including) | 22.3-r1-s1 (including) |
Junos_os_evolved | Juniper | 22.3-r1-s2 (including) | 22.3-r1-s2 (including) |
Junos_os_evolved | Juniper | 22.3-r2 (including) | 22.3-r2 (including) |
Junos_os_evolved | Juniper | 22.3-r2-s1 (including) | 22.3-r2-s1 (including) |
Junos_os_evolved | Juniper | 22.3-r2-s2 (including) | 22.3-r2-s2 (including) |
Junos_os_evolved | Juniper | 22.3-r3-s1 (including) | 22.3-r3-s1 (including) |
Junos_os_evolved | Juniper | 22.3-r3-s2 (including) | 22.3-r3-s2 (including) |
Junos_os_evolved | Juniper | 22.4 (including) | 22.4 (including) |
Junos_os_evolved | Juniper | 22.4-r1 (including) | 22.4-r1 (including) |
Junos_os_evolved | Juniper | 22.4-r1-s1 (including) | 22.4-r1-s1 (including) |
Junos_os_evolved | Juniper | 22.4-r1-s2 (including) | 22.4-r1-s2 (including) |
Junos_os_evolved | Juniper | 22.4-r2 (including) | 22.4-r2 (including) |
Junos_os_evolved | Juniper | 22.4-r2-s1 (including) | 22.4-r2-s1 (including) |
Junos_os_evolved | Juniper | 22.4-r2-s2 (including) | 22.4-r2-s2 (including) |
Junos_os_evolved | Juniper | 23.2 (including) | 23.2 (including) |
Junos_os_evolved | Juniper | 23.2-r1 (including) | 23.2-r1 (including) |
Junos_os_evolved | Juniper | 23.2-r1-s1 (including) | 23.2-r1-s1 (including) |
Junos_os_evolved | Juniper | 23.2-r1-s2 (including) | 23.2-r1-s2 (including) |
Assuming a user with a given identity, authorization is the process of determining whether that user can access a given resource, based on the user’s privileges and any permissions or other access-control specifications that apply to the resource. When access control checks are not applied, users are able to access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures, denial of service, and arbitrary code execution.