CVE-2023-44182
Last modified
CVE-2023-44182 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes unintended effects such as demotion or elevation of privileges associated with an operators actions to occur. Multiple scenarios may occur; for example: privilege escalation over the device or another account, access to files that should not otherwise be accessible, files not being accessible where they should be accessible, code expected to run as non-root may run as root, and so forth. This issue affects: Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S4; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S2; * 22.2 versions prior to 22.2R2-S2, 22.2R3; * 22.3 versions prior to 22.3R1-S2, 22.3R2. Juniper Networks Junos OS Evolved * All versions prior to 21.4R3-S3-EVO; * 22.1-EVO version 22.1R1-EVO and later versions prior to 22.2R2-S2-EVO, 22.2R3-EVO; * 22.3-EVO versions prior to 22.3R1-S2-EVO, 22.3R2-EVO. . EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes unintended effects such as demotion or elevation of privileges associated with an operators actions to occur. Multiple scenarios may occur; for example: privilege escalation over the device or another account, access to files that should not otherwise be accessible, files not being accessible where they should be accessible, code expected to run as non-root may run as root, and so forth. This issue affects: Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S4; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S2; * 22.2 versions prior to 22.2R2-S2, 22.2R3; * 22.3 versions prior to 22.3R1-S2, 22.3R2. Juniper Networks Junos OS Evolved * All versions prior to 21.4R3-S3-EVO; * 22.1-EVO version 22.1R1-EVO and later versions prior to 22.2R2-S2-EVO, 22.2R3-EVO; * 22.3-EVO versions prior to 22.3R1-S2-EVO, 22.3R2-EVO.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | < 20.4 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
| Juniper | Junos | 21.3 | — |
| Juniper | Junos | 21.4 | — |
| Juniper | Junos | 22.1 | — |
| Juniper | Junos | 22.2 | — |
| Juniper | Junos | 22.3 | — |
| Juniper | Junos Os Evolved | < 21.4 | — |
| Juniper | Junos Os Evolved | 21.4 | — |
| Juniper | Junos Os Evolved | 22.1 | R1 |
| Juniper | Junos Os Evolved | 22.2 | R1 |
| Juniper | Junos Os Evolved | 22.3 | R1 |
References
- https://supportportal.juniper.net/JSA73149Vendor Advisory
- https://supportportal.juniper.net/JSA73149Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44182?
How severe is CVE-2023-44182?
How do I fix CVE-2023-44182?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-44175 A Reachable Assertion vulnerability in the routing protocol…7.5
- CVE-2023-44176 A Stack-based Buffer Overflow vulnerability in the CLI comm…5.5
- CVE-2023-44177 A Stack-based Buffer Overflow vulnerability in the CLI comm…5.5
- CVE-2023-44178 A Stack-based Buffer Overflow vulnerability in the CLI comm…5.5
- CVE-2023-4418A remote unprivileged attacker can sent multiple packages to…7.5
- CVE-2023-44181 An Improperly Implemented Security Check for Standard vulne…7.5
- CVE-2023-44183 An Improper Input Validation vulnerability in the VxLAN pac…5.3
- CVE-2023-44184 An Improper Restriction of Operations within the Bounds of …6.5
- CVE-2023-44185 An Improper Input Validation vulnerability in the routing p…7.5
- CVE-2023-44186 An Improper Handling of Exceptional Conditions vulnerabilit…7.5
- CVE-2023-44187An Exposure of Sensitive Information vulnerability in the 'f…5.5
- CVE-2023-44188 A Time-of-check Time-of-use (TOCTOU) Race Condition vulnera…5.3
Are you affected by CVE-2023-44182?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
