CVE-2021-0252: Junos OS: NFX Series: Local Code Execution Vulnerability in JDMD Leads to Privilege Escalation
NFX Series devices using Juniper Networks Junos OS are susceptible to a local code execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. This issue affects Juniper Networks Junos OS on NFX Series: 18.1 version 18.1R1 and later versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S3; 18.4 versions prior to 18.4R2-S5, 18.4R3-S4; 19.1 versions prior to 19.1R1-S3, 19.1R2; 19.2 versions prior to 19.2R1-S5, 19.2R2. This issue does not affect: Juniper Networks Junos OS versions prior to 18.1R1. This issue does not affect the JDMD as used by Junos Node Slicing such as External Servers use in conjunction with Junos Node Slicing and In-Chassis Junos Node Slicing on MX480, MX960, MX2008, MX2010, MX2020.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0252?
CVE-2021-0252 is classified with a high severity level due to the potential for local code execution and privilege escalation.
How do I fix CVE-2021-0252?
To mitigate CVE-2021-0252, users should upgrade their Junos OS to a fixed version as specified by Juniper Networks.
What devices are affected by CVE-2021-0252?
CVE-2021-0252 affects Juniper Networks NFX Series devices running specific versions of Junos OS.
Can CVE-2021-0252 lead to unauthorized access?
Yes, CVE-2021-0252 allows attackers to elevate their privileges, potentially leading to unauthorized access on affected devices.
Is CVE-2021-0252 being actively exploited?
There have been reports of CVE-2021-0252 being actively exploited in the wild, making it critical to address.