Severity
High
Analysis Summary
CVE-2021-31385
Juniper Networks Junos OS could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a path traversal flaw in J-Web. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges as root.
Impact
- Privilege Escalation
Affected Vendors
- Juniper
Affected Products
- Juniper Networks Junos OS 15.1
- Juniper Networks Junos OS 18.3
- Juniper Networks Junos OS 18.4
- Juniper Networks Junos OS 19.1
- Juniper Networks Junos OS 19.2
- Juniper Networks Junos OS 12.3
- Juniper Networks Junos OS 19.3
- Juniper Networks Junos OS 19.4
- Juniper Networks Junos OS 20.1
- Juniper Networks Junos OS 20.2
- Juniper Networks Junos OS 20.3
- Juniper Networks Junos OS 20.4
- Juniper Networks Junos OS 21.1
Remediation
Refer to Juniper Advisory for patch, upgrade, or suggested workaround information.