CVE-2023-28972: Junos OS: NFX Series: 'set system ports console insecure' allows root password recovery
An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on NFX Series systems, leading to a possible administrative bypass with physical access to the console. Password recovery, changing the root password from a console, should not have been allowed from an insecure console. This is similar to the vulnerability described in CVE-2019-0035 but affects different platforms and in turn requires a different fix. This issue affects Juniper Networks Junos OS on NFX Series: 19.2 versions prior to 19.2R3-S7; 19.3 versions prior to 19.3R3-S8; 19.4 versions prior to 19.4R3-S12; 20.2 versions prior to 20.2R3-S8; 20.4 versions prior to 20.4R3-S7; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R3-S1; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28972?
The severity of CVE-2023-28972 has not been explicitly stated but involves improper link resolution which can lead to access control bypass.
How do I fix CVE-2023-28972?
To fix CVE-2023-28972, ensure that the "set system ports console insecure" configuration is disabled to maintain proper access controls.
What versions of Junos OS are affected by CVE-2023-28972?
CVE-2023-28972 affects multiple versions of Junos OS starting from 19.2 up to 22.3.
What product lines are impacted by CVE-2023-28972?
CVE-2023-28972 primarily affects the NFX Series routers using Junos OS.
What type of vulnerability is CVE-2023-28972?
CVE-2023-28972 is classified as an Improper Link Resolution Before File Access vulnerability.