First published: Wed Oct 09 2019(Updated: )
A vulnerability in the Veriexec subsystem of Juniper Networks Junos OS allowing an attacker to fully compromise the host system. A local authenticated user can elevate privileges to gain full control of the system even if they are specifically denied access to perform certain actions. This issue affects: Juniper Networks Junos OS: 12.3X48 versions prior to 12.3X48-D80 on SRX Series.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper JUNOS | =12.3x48 | |
Juniper JUNOS | =12.3x48-d10 | |
Juniper JUNOS | =12.3x48-d15 | |
Juniper JUNOS | =12.3x48-d20 | |
Juniper JUNOS | =12.3x48-d25 | |
Juniper JUNOS | =12.3x48-d30 | |
Juniper JUNOS | =12.3x48-d35 | |
Juniper JUNOS | =12.3x48-d40 | |
Juniper JUNOS | =12.3x48-d45 | |
Juniper JUNOS | =12.3x48-d50 | |
Juniper JUNOS | =12.3x48-d55 | |
Juniper JUNOS | =12.3x48-d60 | |
Juniper JUNOS | =12.3x48-d65 | |
Juniper JUNOS | =12.3x48-d70 | |
Juniper JUNOS | =12.3x48-d75 | |
Juniper Csrx | ||
Juniper SRX100 | ||
Juniper SRX110 | ||
Juniper SRX1400 | ||
Juniper SRX1500 | ||
Juniper SRX210 | ||
Juniper SRX220 | ||
Juniper SRX240 | ||
Juniper SRX300 | ||
Juniper SRX320 | ||
Juniper SRX340 | ||
Juniper SRX3400 | ||
Juniper SRX345 | ||
Juniper SRX3600 | ||
Juniper SRX4100 | ||
Juniper SRX4200 | ||
Juniper SRX4600 | ||
Juniper SRX5400 | ||
Juniper SRX550 | ||
Juniper SRX550 | ||
juniper srx5600 | ||
Juniper SRX5800 | ||
Juniper SRX650 | ||
Juniper vSRX |
The following software releases have been updated to resolve this specific issue: Junos OS: 12.3X48-D80 and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0058 is a vulnerability in the Veriexec subsystem of Juniper Networks Junos OS that allows an attacker to fully compromise the host system.
CVE-2019-0058 has a severity score of 7.8, indicating a high severity.
CVE-2019-0058 affects Juniper JUNOS version 12.3x48 and its subsequent releases.
CVE-2019-0058 can be exploited by a local authenticated user to elevate privileges and gain full control of the system, even if they are denied access to perform certain actions.
Additional information about CVE-2019-0058 can be found on the Juniper Networks Knowledge Base at the following link: [https://kb.juniper.net/JSA10956](https://kb.juniper.net/JSA10956)