Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
Published Apr 10, 2019
6.8
MEDIUMCVSS 3.1
EPSS 0.40%
Description
When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems booted from an OAM (Operations, Administration, and Maintenance) volume, leading to a possible administrative bypass with physical access to the console. OAM volumes (e.g. flash drives) are typically instantiated as /dev/gpt/oam, or /oam for short. Password recovery, changing the root password from a console, should not have been allowed from an insecure console. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D160; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D496, 15.1X53-D68; 16.1 versions prior to 16.1R3-S10, 16.1R6-S6, 16.1R7-S3; 16.1X65 versions prior to 16.1X65-D49; 16.2 versions prior to 16.2R2-S8; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S6, 17.4R2-S2; 18.1 versions prior to 18.1R2-S4, 18.1R3-S3; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S2. This issue does not affect Junos OS releases prior to 15.1.
Affected products
-
- Version 15.1StatusaffectedConstraints<15.1F6-S12, 15.1R7-S3
- Version 15.1X49StatusaffectedConstraints<15.1X49-D160
- Version 15.1X53StatusaffectedConstraints<15.1X53-D236, 15.1X53-D496, 15.1X53-D68
- Version 16.1StatusaffectedConstraints<16.1R3-S10, 16.1R6-S6, 16.1R7-S3
- Version 16.1X65StatusaffectedConstraints<16.1X65-D49
- Version 16.2StatusaffectedConstraints<16.2R2-S8
- Version 17.1StatusaffectedConstraints<17.1R2-S10, 17.1R3
- Version 17.2StatusaffectedConstraints<17.2R1-S8, 17.2R3-S1
- Version 17.3StatusaffectedConstraints<17.3R3-S3
- Version 17.4StatusaffectedConstraints<17.4R1-S6, 17.4R2-S2
- Version 18.1StatusaffectedConstraints<18.1R2-S4, 18.1R3-S3
- Version 18.2StatusaffectedConstraints<18.2R2
- Version 18.2X75StatusaffectedConstraints<18.2X75-D40
- Version 18.3StatusaffectedConstraints<18.3R1-S2
- Version allStatusunaffectedConstraints<15.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
Configuration 1
Configuration 2
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
- 15.1x49
Configuration 3
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
- 15.1x53
Configuration 4
Configuration 6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: Junos OS 15.1F6-S12, 15.1R7-S3, 15.1X49-D160, 15.1X53-D236, 15.1X53-D496, 15.1X53-D68, 16.1R3-S10, 16.1R6-S6, 16.1R7-S3, 16.1X65-D49, 16.2R2-S8, 17.1R2-S10, 17.1R3, 17.2R1-S8, 17.2R3-S1, 17.3R3-S3, 17.4R1-S6, 17.4R2-S2, 18.1R2-S4, 18.1R3-S3, 18.2R2, 18.2X75-D40, 18.3R1-S2, 18.4R1, and all subsequent releases.
References (1)
- https://kb.juniper.net/JSA10924 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://kb.juniper.net/JSA10924 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.