CVE-2019-0061: Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation
The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and is granted special permission to open this protected mode socket. Due to a misconfiguration of the internal socket, a local, authenticated user may be able to exploit this vulnerability to gain administrative privileges. This issue only affects Linux-based platforms. FreeBSD-based platforms are unaffected by this vulnerability. Exploitation of this vulnerability requires Junos shell access. This issue cannot be exploited from the Junos CLI. This issue affects Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D171, 15.1X49-D180; 15.1X53 versions prior to 15.1X53-D496, 15.1X53-D69; 16.1 versions prior to 16.1R7-S4; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R2-S7, 17.2R3-S1; 17.3 versions prior to 17.3R3-S4; 17.4 versions prior to 17.4R1-S6, 17.4R1-S7, 17.4R2-S3, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S4; 18.2 versions prior to 18.2R1-S5, 18.2R2-S2, 18.2R3; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0061?
CVE-2019-0061 has a medium severity rating, indicating a moderate risk to systems.
How do I fix CVE-2019-0061?
To fix CVE-2019-0061, update Junos OS to the latest version provided by Juniper Networks that addresses the vulnerability.
What systems are affected by CVE-2019-0061?
CVE-2019-0061 affects multiple versions of Junos OS, including 15.1x49 and various updates under 16.x and 17.x.
What type of vulnerability is CVE-2019-0061?
CVE-2019-0061 is a misconfiguration vulnerability in the management daemon of Junos OS.
Is there a workaround for CVE-2019-0061?
Currently, the recommended mitigation for CVE-2019-0061 is to apply the patches or upgrades provided by Juniper Networks.