Description
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This issue affects Juniper Networks Junos OS 20.2 version 20.2R1 and later versions prior to 21.2R1 on cSRX Series.
Problem types
CWE-257 Storing Passwords in a Recoverable Format
Privilege elevation
Product status
20.2R1 (custom) before 20.2*
20.3R1 (custom) before 20.3*
20.4R1 (custom) before 20.4*
21.1R1 (custom) before 21.1*