CVE-2023-28966
HIGHJuniper Networks Junos OS Evolved <20.4R3-S5-EVO, <21.2R3-EVO - Pri...
Title source: llmDescription
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and directory permissions on certain system files, allowing an attacker with access to these files and folders to inject CLI commands as root. This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S5-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO.
References (1)
Core 1
Core References
Vendor Advisory
https://supportportal.juniper.net/JSA70590
Scores
CVSS v3
7.8
EPSS
0.0003
EPSS Percentile
9.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (4)
juniper/junos_os_evolved
20.4 (13 CPE variants)
juniper/junos_os_evolved
21.2 (7 CPE variants)
juniper/junos_os_evolved
21.3 (3 CPE variants)
juniper/junos_os_evolved
< 20.4
Published
Apr 17, 2023
Tracked Since
Feb 18, 2026