An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.
The On-Box Anomaly Detection service should be accessible only to internal system processes through an internal routing instance. In vulnerable software versions, however, this service is exposed on an externally accessible network port, allowing unauthorized network access. Attackers can contact this service directly, manipulate it, and consequently execute arbitrary code with root privileges on the device. The error results from incorrect permission assignment to a critical resource (CWE-732).
Attackers gain full control of the device with root privileges, enabling configuration reading and modification, malicious software installation, device disruption, or use as a network entry point.
Update Junos OS Evolved to version 25.4R1-S1-EVO or 25.4R2-EVO. Until the patch is deployed, it is recommended to restrict network access to PTX series devices using firewalls or ACLs to prevent external hosts from communicating with the vulnerable service. Details available in producer bulletin JSA107128.
Juniper Junos OS Evolved version 25.4R1-EVO and 25.4 before 25.4R1-S1-EVO and 25.4R2-EVO running on PTX series devices: PTX10001-36MR, PTX10002-36QDD, PTX10003, PTX10004. The issue does not affect Junos OS Evolved versions earlier than 25.4R1-EVO or Junos OS systems.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:RedJuniper Junos Os Evolved
OSJuniper25.4Juniper Ptx10001 36mr
HWJuniperall versionsJuniper Ptx10002 36qdd
HWJuniperall versionsJuniper Ptx10003
HWJuniperall versionsJuniper Ptx10004
HWJuniperall versionsJuniper Ptx10008
HWJuniperall versionsJuniper Ptx10016
HWJuniperall versions
Related vulnerabilities
Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message
DoS w Juniper Junos OS Evolved – awaria procesu evo-aftmand przy unilist ECMP
DoS w RPD Juniper Junos OS przez złośliwą aktualizację BGP
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forward...
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Jun...