CVE-2023-44187: Junos OS Evolved: 'file copy' CLI command can disclose password to shell users
An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell access to view passwords supplied on the CLI command-line. These credentials can then be used to provide unauthorized access to the remote system.
This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S7-EVO; 21.1 versions 21.1R1-EVO and later; 21.2 versions prior to 21.2R3-S5-EVO; 21.3 versions prior to 21.3R3-S4-EVO; 21.4 versions prior to 21.4R3-S4-EVO; 22.1 versions prior to 22.1R3-S2-EVO; 22.2 versions prior to 22.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44187?
CVE-2023-44187 is classified as a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2023-44187?
To mitigate CVE-2023-44187, you should upgrade Junos OS Evolved to a version that addresses this vulnerability.
Who is affected by CVE-2023-44187?
CVE-2023-44187 affects local, authenticated users with shell access on specific versions of Junos OS Evolved.
What type of exposure does CVE-2023-44187 entail?
CVE-2023-44187 allows an attacker to view sensitive passwords input via the command line interface.
What can attackers do with the information exposed by CVE-2023-44187?
Attackers can utilize the exposed passwords from CVE-2023-44187 to gain unauthorized access to remote systems.