CVE-2023-44194: Junos OS: An unauthenticated attacker with local access to the device can create a backdoor with root privileges
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to create a backdoor with root privileges. The issue is caused by improper directory permissions on a certain system directory, allowing an attacker with access to this directory to create a backdoor with root privileges.
This issue affects Juniper Networks Junos OS:
All versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-44194.
What is the severity of CVE-2023-44194?
The severity of CVE-2023-44194 is high (CVSS score: 7.8).
What is the affected software?
The affected software is Juniper Networks Junos OS versions up to 20.4.
How can an attacker exploit this vulnerability?
An unauthenticated attacker with local access to the device can create a backdoor with root privileges by exploiting this vulnerability in Juniper Networks Junos OS.
How can I fix CVE-2023-44194?
To fix CVE-2023-44194, it is recommended to upgrade Juniper Networks Junos OS to version 21.4 or apply the necessary patches provided by Juniper Networks.