CVE-2021-31350 Information
Description
An Improper Privilege Management vulnerability in the gRPC framework used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved allows a network-based low-privileged authenticated attacker to perform operations as root leading to complete compromise of the targeted system. The issue is caused by the JET service daemon (jsd) process authenticating the user then passing configuration operations directly to the management daemon (mgd) process which runs as root. This issue affects Juniper Networks Junos OS: 18.4 versions prior to 18.4R1-S8 18.4R2-S8 18.4R3-S8; 19.1 versions prior to 19.1R2-S3 19.1R3-S5; 19.2 versions prior to 19.2R1-S7 19.2R3-S2; 19.3 versions prior to 19.3R2-S6 19.3R3-S2; 19.4 versions prior to 19.4R1-S4 19.4R2-S4 19.4R3-S3; 20.1 versions prior to 20.1R2-S2 20.1R3; 20.2 versions prior to 20.2R2-S3 20.2R3; 20.3 versions prior to 20.3R2-S1 20.3R3; 20.4 versions prior to 20.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 18.4R1. Juniper Networks Junos OS Evolved: All versions prior to 20.4R2-EVO; 21.1-EVO versions prior to 21.1R2-EVO.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://kb.juniper.net/JSA11215
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: