CVE-2021-0248

CRITICAL

Juniper Networks Junos OS <19.1R1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an attacker to take over any instance of an NFX deployment. This issue is only exploitable through administrative interfaces. This issue affects: Juniper Networks Junos OS versions prior to 19.1R1 on NFX Series. No other platforms besides NFX Series devices are affected.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://kb.juniper.net/JSA11141

Scores

CVSS v3 10.0
EPSS 0.0042
EPSS Percentile 62.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
juniper/junos 19.1
juniper/junos < 19.1
Published Apr 22, 2021
Tracked Since Feb 18, 2026