Loading HuntDB...

GHSA-556v-xwc9-3f54

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their privileges to 'root' leading to a full compromise of the system.

The Junos OS Evolved CLI doesn't properly handle command options in some cases, allowing users which execute specific CLI commands with a crafted set of parameters to escalate their privileges to root on shell level.

This issue affects Junos OS Evolved: 

* 21.1-EVO versions 21.1R1-EVO and later before 21.2R3-S8-EVO, 
* 21.4-EVO versions before 21.4R3-S7-EVO,
* 22.1-EVO versions before 22.1R3-S6-EVO, 
* 22.2-EVO versions before 22.2R3-EVO,
* 22.3-EVO versions before 22.3R2-EVO.

Related CVEs

Key Information

GHSA ID
GHSA-556v-xwc9-3f54
Published
July 11, 2024 6:31 PM
Last Modified
September 23, 2024 3:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.