CVE-2019-0061 describes a privilege escalation vulnerability in the Junos OS management daemon (MGD) on Linux-based platforms. A misconfiguration of an internal Unix-domain socket allows a local, authenticated user with Junos shell access to gain administrative privileges. This vulnerability affects numerous versions of Juniper Networks Junos OS, but not FreeBSD-based platforms. The vulnerability has a CVSS score of 7.8 (High), indicating a significant risk. It requires local access and low attack complexity, allowing an attacker to achieve high confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, nor is public exploit code available (e.g., Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.1, < 16.1R7-S4CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 16.2, < 16.2R2-S9CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 17.1, < 17.1R3CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 17.3, < 17.3R3-S4CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
15.1x49CPE matchmatch criteria | cpe:2.3:o:juniper:junos:15.1x49:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.