CVE-2017-2341
An insufficient authentication vulnerability on platforms where Junos OS instances are run in a virtualized environment, may allow unprivileged users on the Junos OS instance to gain access to the host operating environment, and thus escalate privileges. Affected releases are Juniper Networks Junos OS 14.1X53 prior to 14.1X53-D40 on QFX5110, QFX5200, QFX10002, QFX10008, QFX10016, EX4600 and NFX250; 15.1 prior to 15.1R5 on EX4600; 15.1X49 prior to 15.1X49-D70 on vSRX, SRX1500, SRX4100, SRX4200; 16.1 prior to 16.1R2 on EX4600, ACX5000 series. This issue does not affect vMX. No other Juniper Networks products or platforms are affected by this issue.
Published:Jul 14, 2017
Last Modified:Apr 20, 2025
EPS:Jul 14, 2017
EPSS Score:0.00191
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Juniper
Product
Acx5000
Juniper
Acx5000
Vendor
Juniper
Product
Ex4600
Juniper
Ex4600
Vendor
Juniper
Product
Junos
Juniper
Junos
Vendor
Juniper
Product
Nfx250
Juniper
Nfx250
Vendor
Juniper
Product
Qfx10002
Juniper
Qfx10002
Vendor
Juniper
Product
Qfx10008
Juniper
Qfx10008
Vendor
Juniper
Product
Qfx10016
Juniper
Qfx10016
Vendor
Juniper
Product
Qfx5110
Juniper
Qfx5110
Vendor
Juniper
Product
Qfx5200
Juniper
Qfx5200
Vendor
Juniper
Product
Srx1500
Juniper
Srx1500
Vendor
Juniper
Product
Srx4100
Juniper
Srx4100
Vendor
Juniper
Product
Srx4200
Juniper
Srx4200
Vendor
Juniper
Product
Vsrx
Juniper
Vsrx
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
