Junos OS: ethtraceroute Local Privilege Escalation vulnerability in SUID binaries
Junos OS: ethtraceroute Local Privilege Escalation vulnerability in SUID binaries
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
The following software releases have been updated to resolve this specific issue: Junos OS 15.1X49-D240, 17.3R3-S11, 17.4R3-S4, 18.1R3-S12, 18.2R3-S7, 18.4R2-S7, 19.1R1-S6, 19.1R2-S2, 19.1R3-S4, 19.3R3-S2, 19.4R3-S1, 20.1R2, 20.1R3, 20.2R2-S1, 20.2R3, 20.3R1-S1, 21.1R1, and all subsequent releases. As a proactive measure to tighten the security of other Ethernet OAM utilities, setuid was also removed from other binaries, including ethping, ethdm, ethslm and ethlm.