Junos OS: QFX5200 and QFX10002: Unintended ONIE partition was shipped with certain Junos OS .bin and .iso images
Published Jul 11, 2018
9.8
CRITICALCVSS 3.0
EPSS 1.25%
Description
QFX5200 and QFX10002 devices that have been shipped with Junos OS 15.1X53-D21, 15.1X53-D30, 15.1X53-D31, 15.1X53-D32, 15.1X53-D33 and 15.1X53-D60 or have been upgraded to these releases using the .bin or .iso images may contain an unintended additional Open Network Install Environment (ONIE) partition. This additional partition allows the superuser to reboot to the ONIE partition which will wipe out the content of the Junos partition and its configuration. Once rebooted, the ONIE partition will not have root password configured, thus any user can access the console or SSH, using an IP address acquired from DHCP, as root without password. Once the device has been shipped or upgraded with the ONIE partition installed, the issue will persist. Simply upgrading to higher release via the CLI will not resolve the issue. No other Juniper Networks products or platforms are affected by this issue.
Affected products
-
- Version 15.1X53StatusaffectedConstraints<15.1X53-D60
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
In order to resolve this issue (remove the ONIE partition from the device), customer needs to reimage the device using the USB or PXE image from the Juniper download page. The affected Junos image files have been removed from the Juniper download page.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.25% (0.01254) | 68.40th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.25% (0.01254) | 68.16th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.22% (0.00220) | 60.41th | v3 (v2023.03.01) |
| Dec 2, 2023 | 0.22% (0.00220) | 59.67th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.23% (0.00230) | 59.35th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.62% (0.00624) | 17.80th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
No CWE recorded.
References (2)
- http://www.securitytracker.com/id/1041336 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://kb.juniper.net/JSA10869 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securitytracker.com/id/1041336 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://kb.juniper.net/JSA10869 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.