A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers. This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400: * 23.2R2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:* | ||
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:* | ||
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.2:r2-s2:*:*:*:*:*:* | ||
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.2:r2-s3:*:*:*:*:*:* | ||
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.2:r2-s4:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.