CVE-2019-0058 is a high-severity privilege escalation vulnerability in the Veriexec subsystem of Juniper Networks Junos OS, affecting specific 12.3X48 versions on SRX Series devices. A local authenticated user can exploit this flaw to gain full control of the host system, bypassing intended access restrictions. With a CVSS score of 7.8, this vulnerability presents a significant risk due to its low attack complexity and complete compromise potential (confidentiality, integrity, and availability). Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.3X48, < 12.3X48-D80CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:-:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:* | ||
12.3x48CPE matchmatch criteria | cpe:2.3:o:juniper:junos:12.3x48:d20:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.