An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell access to view passwords supplied on the CLI command-line. These credentials can then be used to provide unauthorized access to the remote system. This issue affects Juniper Networks Junos OS Evolved: * All versions prior to 20.4R3-S7-EVO; * 21.1 versions 21.1R1-EVO and later; * 21.2 versions prior to 21.2R3-S5-EVO; * 21.3 versions prior to 21.3R3-S4-EVO; * 21.4 versions prior to 21.4R3-S4-EVO; * 22.1 versions prior to 22.1R3-S2-EVO; * 22.2 versions prior to 22.2R2-EVO.
The following software releases have been updated to resolve this specific issue: Junos OS Evolved 20.4R3-S7-EVO, 21.2R3-S5-EVO, 21.3R3-S4-EVO, 21.4R3-S4-EVO, 22.1R3-S2-EVO, 22.2R2-EVO, 22.3R1-EVO, and all subsequent releases.
Restrict Junos OS Evolved shell access to trusted users only. Avoid or disallow the use of the 'file copy' command.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS Evolved | <20.4R3-S7-EVO | 20.4R3-S7-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=21.1R1<21.1* | 21.1* | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=21.2<21.2R3-S5-EVO | 21.2R3-S5-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=21.3<21.3R3-S4-EVO | 21.3R3-S4-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=21.4<21.4R3-S4-EVO | 21.4R3-S4-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=22.1<22.1R3-S2-EVO | 22.1R3-S2-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=22.2<22.2R2-EVO | 22.2R2-EVO | advisory ↗ |