VYPR
Unrated severityNVD Advisory· Published Apr 22, 2021· Updated Sep 16, 2024

Junos OS: Junos Fusion: Hard-coded credentials on satellite devices allows a locally authenticated attacker to elevate their privileges.

CVE-2021-0245

Description

A Use of Hard-coded Credentials vulnerability in Juniper Networks Junos OS on Junos Fusion satellite devices allows an attacker who is local to the device to elevate their privileges and take control of the device. This issue affects: Juniper Networks Junos OS Junos Fusion Satellite Devices. 16.1 versions prior to 16.1R7-S7; 17.1 versions prior to 17.1R2-S12, 17.1R3-S2; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S10; 17.4 version 17.4R3 and later versions; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3; 18.3 versions prior to 18.3R1-S7, 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R1-S6, 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S4, 19.2R2; 19.3 versions prior to 19.3R2-S5, 19.3R3; 19.4 versions prior to 19.4R1-S1, 19.4R2; 20.1 versions prior to 20.1R1-S1, 20.1R2. This issue does not affected Junos OS releases prior to 16.1R1 or all 19.2R3 and 19.4R3 release versions.

Affected products

2
  • Juniper Networks/Junosllm-fuzzy2 versions
    16.1 before 16.1R7-S7; 17.1 before 17.1R2-S12, 17.1R3-S2; 17.2 before 17.2R3-S4; 17.3 before 17.3R3-S8; 17.4 before 17.4R2-S10, 17.4R3+; 18.1 before 18.1R3-S10; 18.2 before 18.2R2-S7, 18.2R3-S3; 18.3 before 18.3R1-S7, 18.3R2-S4, 18.3R3-S2; 18.4 before 18.4R1-S6, 18.4R2-S4, 18.4R3-S1; 19.1 before 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 before 19.2R1-S4, 19.2R2; 19.3 before 19.3R2-S5, 19.3R3; 19.4 before 19.4R1-S1, 19.4R2; 20.1 before 20.1R1-S1, 20.1R2+ 1 more
    • (no CPE)range: 16.1 before 16.1R7-S7; 17.1 before 17.1R2-S12, 17.1R3-S2; 17.2 before 17.2R3-S4; 17.3 before 17.3R3-S8; 17.4 before 17.4R2-S10, 17.4R3+; 18.1 before 18.1R3-S10; 18.2 before 18.2R2-S7, 18.2R3-S3; 18.3 before 18.3R1-S7, 18.3R2-S4, 18.3R3-S2; 18.4 before 18.4R1-S6, 18.4R2-S4, 18.4R3-S1; 19.1 before 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 before 19.2R1-S4, 19.2R2; 19.3 before 19.3R2-S5, 19.3R3; 19.4 before 19.4R1-S1, 19.4R2; 20.1 before 20.1R1-S1, 20.1R2
    • (no CPE)range: 16.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.