Juniper Networks Junos OS 15.1X49 Improper Privilege Management Vulnerability

Summary

The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and is granted special permission to open this protected mode socket. Due to a misconfiguration of the internal socket, a local, authenticated user may be able to exploit this vulnerability to gain administrative privileges. 

Credit:

The information has been provided by Vendor

The original article can be found at:https://kb.juniper.net/JSA10960


Details

This issue only affects Linux-based platforms. FreeBSD-based platforms are unaffected by this vulnerability. Exploitation of this vulnerability requires Junos shell access. This issue cannot be exploited from the Junos CLI.

Vulnerable Systems:

Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D171

CVE Information:

CVE-2019-0061

Disclosure Timeline:
Published Date:10/09/2019