CVE-2021-0255: Junos OS: ethtraceroute Local Privilege Escalation vulnerability in SUID binaries
A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticated user with shell access to escalate privileges and write to the local filesystem as root. ethtraceroute is shipped with setuid permissions enabled and is owned by the root user, allowing local users to run ethtraceroute with root privileges. This issue affects Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D240; 17.3 versions prior to 17.3R3-S11, 17.4 versions prior to 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R3-S7; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S7; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S4; 19.3 versions prior to 19.3R3-S2; 19.4 versions prior to 19.4R3-S1; 20.1 versions prior to 20.1R2, 20.1R3; 20.2 versions prior to 20.2R2-S1, 20.2R3; 20.3 versions prior to 20.3R1-S1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0255?
CVE-2021-0255 has been classified with a high severity rating due to its potential for local privilege escalation.
Who is affected by CVE-2021-0255?
CVE-2021-0255 affects authenticated users with shell access on specific versions of Juniper Networks Junos OS.
How do I fix CVE-2021-0255?
To fix CVE-2021-0255, apply the appropriate Junos OS updates as outlined in the vendor's security advisory.
What does CVE-2021-0255 allow attackers to do?
CVE-2021-0255 allows attackers to escalate privileges to root and write to the local filesystem.
Is there a workaround for CVE-2021-0255?
While no specific workaround is recommended, limiting shell access for users may help mitigate the risk of CVE-2021-0255.