CVE-2018-0053 MEDIUM

CVE-2018-0053: vSRX Series: A local authentication vulnerability may lead to full control of a vSRX instance while the system is booting.

Vendor Juniper Networks
Product Junos OS
Published October 10, 2018
Last update September 17, 2024

CVSS base score

6.8/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX.

Key dates

02Disclosure timeline

October 10, 2018 CVE published
September 17, 2024 Record updated