CVE-2019-0035
Published Apr 10, 2019
Last updated 4 years ago
Overview
- Description
- When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems booted from an OAM (Operations, Administration, and Maintenance) volume, leading to a possible administrative bypass with physical access to the console. OAM volumes (e.g. flash drives) are typically instantiated as /dev/gpt/oam, or /oam for short. Password recovery, changing the root password from a console, should not have been allowed from an insecure console. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D160; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D496, 15.1X53-D68; 16.1 versions prior to 16.1R3-S10, 16.1R6-S6, 16.1R7-S3; 16.1X65 versions prior to 16.1X65-D49; 16.2 versions prior to 16.2R2-S8; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S6, 17.4R2-S2; 18.1 versions prior to 18.1R2-S4, 18.1R3-S3; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S2. This issue does not affect Junos OS releases prior to 15.1.
- Source
- sirt@juniper.net
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
CVSS 3.0
- Type
- Secondary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:15.1:f2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C56E6C3-BBB6-4853-91D9-99C7676D0CD4" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:f3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E0ECBD8-3D66-49DA-A557-5695159F0C06" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:f4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EAA2998-A0D6-4818-9E7C-25E8099403E7" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:f5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D4ADFC5-D4B8-4A68-95D8-8ADF92C1CFE8" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:f6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71D211B9-B2FE-4324-AAEE-8825D5238E48" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:f7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD332D86-5DA7-49A4-98C3-E4D946832DC1" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0D3EA8F-4D30-4383-AF2F-0FB6D822D0F3" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E6CD065-EC06-4846-BD2A-D3CA7866070F" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:r3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7620D01-1A6B-490F-857E-0D803E0AEE56" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:r4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A1545CE-279F-4EE2-8913-8F3B2FAFE7F6" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:r5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08FC0245-A4FF-42C0-A236-8569301E351A" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1:r6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "120EA9E3-788B-4CFD-A74F-17111FFD0131" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D90D8985-34EF-44CC-A9A7-CB0FD22676F2" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d100:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "856A5668-FA4F-44E9-A3F0-BE4979F631E2" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d110:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3B2DA4D-5E5D-4E09-BE4D-5B3371703D8F" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d120:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA2459ED-DFA5-4701-AF92-C2928C3BD64D" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d130:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8830C4BC-2B3D-4CCF-A37E-79C2D46159BD" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d150:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E288F54B-AEA3-412F-85A4-EBDFE74DB84F" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18468579-0195-4DDE-BAA5-4BE4068F3A69" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d30:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E5FAA97-171F-4DB9-B78E-6E1A5F34336A" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d35:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "870244F3-1C05-4F10-A205-5189BB860F46" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d40:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "235EE40B-AA15-4F39-8087-A051F4F70995" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d45:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17330544-3AFC-463E-A146-2840A8AE17D2" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d50:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8ABA301F-7866-42A5-8391-E07BEAFF06FA" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d60:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1901864B-688B-4352-A587-4B96B4E49FB1" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d65:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78F53FBF-C6D8-4AE5-87EC-9D9F88DCEFB9" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d70:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B6670FB-9F5A-469B-97F2-074C28572065" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d75:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71198992-83AA-4E28-BA7D-A3C1897B5E2B" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d80:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4323D874-C317-4D76-8E2D-C82376D84CBE" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x49:d90:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F56067DA-EBA9-481A-B60B-52148584EFBD" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E87C765-8D68-404A-AC71-3F22A7260E8C" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d20:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E3B807C-196D-42B8-9042-7582A1366772" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d21:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83FEEE8F-9279-46F2-BAF9-A60537020C61" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d210:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBD36C0D-0F44-4349-968D-4CD60F281D84" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d230:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E364FE2-5FB1-4E14-8DF5-CA21F4BFBBC5" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d231:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F22C4C2-20E0-428F-A9BF-37E8BD63A9E3" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d232:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71334963-7BF1-49DB-84E6-D6F2A927458B" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d233:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E773AA7F-AB97-488A-B73D-682FB5553B31" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d25:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1DD0B95A-7C9F-4A18-9CD8-BA344DEFC9D4" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d30:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F294E43-73FA-4EF3-90F2-EE29C56D6573" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d32:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDDE1048-BFEA-4A3E-8270-27C538A68837" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d33:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC517CD0-FF35-498F-AD33-683B43CA3829" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d34:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53F7E1C5-BFA9-426C-9F95-3EA5DB458C7E" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d40:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2B5ED13-F998-447C-8FEA-047FE9FE2F4B" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d45:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65F3CD2A-D5E1-4EFF-9013-6D81B396F765" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d495:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "723FD85C-C763-4017-B6BF-0CA707997D2A" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d56:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3978B35D-5745-47BC-A56F-A0678AB0F3E8" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d60:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "962CCED8-E321-4878-9BE6-0DC33778559A" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d61:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B08B97A-5D4D-405B-A1C4-9E327E4EED35" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d62:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "738C1061-E8B8-4924-AFE9-5E59F22CA4A8" }, { "criteria": "cpe:2.3:o:juniper:junos:15.1x53:d63:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9071DC8C-D0AA-448E-82BF-7C801199193F" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:16.1:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBE35BDC-7739-4854-8BB8-E8600603DE9D" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DC47132-9EEA-4518-8F86-5CD231FBFB61" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1:r3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD5A30CE-9498-4007-8E66-FD0CC6CF1836" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1:r4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D3E38C1-808C-4BD3-993D-F30855F5390F" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1:r5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72194CB7-FFDC-4897-9D6E-EA3459DDDEB5" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1:r6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92F35C19-5AD2-4F98-8313-2E880714DF3B" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1:r7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B4A4960-0241-4BF4-8857-8B7BE33466B6" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:17.3:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38A40E03-F915-4888-87B0-5950F75F097D" }, { "criteria": "cpe:2.3:o:juniper:junos:17.3:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69FC46D4-39E2-4E2F-A1D3-1001769A7115" }, { "criteria": "cpe:2.3:o:juniper:junos:17.3:r3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25C7C3D0-A203-4979-8375-A610ADD48E9E" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:17.2:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E889BF9C-BDDF-4A6A-97BB-00A097EF6D91" }, { "criteria": "cpe:2.3:o:juniper:junos:17.2:r1-s7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9689695F-53EB-4B35-9072-750E7282B011" }, { "criteria": "cpe:2.3:o:juniper:junos:17.2:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D45F2C3-20FF-4A91-A440-E109B3CCE7C9" }, { "criteria": "cpe:2.3:o:juniper:junos:17.2:r3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11E055AC-5626-4EBB-8611-17BB1E8AEF15" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:17.4:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "988D317A-0646-491F-9B97-853E8E208276" }, { "criteria": "cpe:2.3:o:juniper:junos:17.4:r1-s7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0F65DCA-34B9-4CE8-91C9-426AAAEB4097" }, { "criteria": "cpe:2.3:o:juniper:junos:17.4:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E0CE79A-157D-47DE-BE65-936BC12470EB" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:18.1:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0A756E2-C320-405A-B24F-7C5022649E5A" }, { "criteria": "cpe:2.3:o:juniper:junos:18.1:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2EF6F4C1-6A7E-474F-89BC-7A3C50FD8CAC" }, { "criteria": "cpe:2.3:o:juniper:junos:18.1:r3-s2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C97683B3-A07B-428F-9535-C49B55305679" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:18.2:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "167EEC4F-729E-47C2-B0F8-E8108CE3E985" }, { "criteria": "cpe:2.3:o:juniper:junos:18.2:r1-s3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A893CCE5-96B8-44A1-ABEF-6AB9B527B2FB" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:18.3:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5342C3DC-D640-47AB-BD76-3444852988A2" }, { "criteria": "cpe:2.3:o:juniper:junos:18.3:r1-s1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8AB8585E-EDC6-4400-BEE3-3A6A7C922C90" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:18.2x75:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "097AEA48-4A45-489E-9C91-D5CE139994D2" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:16.1x65:d30:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A347C15-3ABC-4B11-A9BB-5DF1C73538EE" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1x65:d35:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBCD72E3-22CE-4E9E-9CC5-686C4B163116" }, { "criteria": "cpe:2.3:o:juniper:junos:16.1x65:d40:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46A11513-B901-4E12-8AA7-54D4794595D2" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:17.1:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7572C187-4D58-4E0D-A605-B2B13EFF5C6B" }, { "criteria": "cpe:2.3:o:juniper:junos:17.1:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E34A149E-C2ED-4D86-A105-0A2775654AE7" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:juniper:junos:16.2:r1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3661BC68-6F32-447F-8D20-FD73FBBED9C6" }, { "criteria": "cpe:2.3:o:juniper:junos:16.2:r2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B6097D4-3856-4696-9A26-5B6C0FD9AD6C" }, { "criteria": "cpe:2.3:o:juniper:junos:16.2:r2-s7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A7231C6-1CC4-4E7A-A317-5315246D2540" } ], "operator": "OR" } ] } ]