CVE-2024-39512 describes an Improper Physical Access Control vulnerability in Juniper Networks Junos OS Evolved versions 23.2R2-EVO before 23.2R2-S1-EVO and 23.4R1-EVO before 23.4R2-EVO. An attacker with physical access can exploit this by disconnecting and reconnecting the console cable, resuming a previous session to potentially gain administrative privileges. This vulnerability has a CVSS score of 6.6 (Medium), indicating a physical attack vector with low complexity but high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.2:r2:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s1:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s2:*:*:*:*:*:* | ||
>= 23.2R2-EVO, < 23.2R2-S1-EVOCPE match | cpe:2.3:o:juniper:junos_os_evolved:*:r1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.