« Back to list

CVE-2021-0278

Status: ModifiedHigh (7.8)—

An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S3 junos:19.4R1-S4 junos:19.4R3-S4 junos:20.1R2-S2 junos:20.1R3 junos:20.2R3-S1 junos:20.3X75-D20 junos:20.3X75-D30 junos:20.4R2-S1 junos:20.4R3 junos:21.1R1-S1 junos:21.1R2 junos:21.2R1 junos:21.3R1 This issue affects: Juniper Networks Junos OS 19.3 versions 19.3R1 and above prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R2-S2, 20.1R3-S1; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3; 20.4 versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2.

Read full descriptionShow less

This issue does not affect Juniper Networks Junos OS versions prior to 19.3R1.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2021-0278",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS",
          "versions": [
            {
              "status": "unaffected",
              "version": "unspecified",
              "lessThan": "19.3R1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "19.3R2-S6, 19.3R3-S3",
                  "status": "unaffected"
                }
              ],
              "version": "19.3R1",
              "lessThan": "19.3*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "19.4",
              "lessThan": "19.4R3-S5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.1",
              "lessThan": "20.1R2-S2, 20.1R3-S1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.2",
              "lessThan": "20.2R3-S2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.3",
              "lessThan": "20.3R3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.4",
              "lessThan": "20.4R2-S1, 20.4R3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "21.1",
              "lessThan": "21.1R1-S1, 21.1R2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-15T20:15:09.450",
  "references": [
    {
      "url": "https://kb.juniper.net/JSA11182",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "https://kb.juniper.net/JSA11182",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "sirt@juniper.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S3 junos:19.4R1-S4 junos:19.4R3-S4 junos:20.1R2-S2 junos:20.1R3 junos:20.2R3-S1 junos:20.3X75-D20 junos:20.3X75-D30 junos:20.4R2-S1 junos:20.4R3 junos:21.1R1-S1 junos:21.1R2 junos:21.2R1 junos:21.3R1 This issue affects: Juniper Networks Junos OS 19.3 versions 19.3R1 and above prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R2-S2, 20.1R3-S1; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3; 20.4 versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 19.3R1."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Comprobación de Entrada Inapropiada en J-Web de Juniper Networks Junos OS permite a un atacante autenticado localmente escalar sus privilegios hasta convertirse en root en el dispositivo de destino. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19. 3R2-S6 junos:19.3R3-S3 junos:19.4R1-S4 junos:19.4R3-S4 junos:20.1R2-S2 junos:20.1R3 junos:20.2R3-S1 junos:20.3X75-D20 junos:20. 3X75-D30 junos:20.4R2-S1 junos:20.4R3 junos:21.1R1-S1 junos:21.1R2 junos:21.2R1 junos:21.3R1 Este problema afecta a versiones de: Juniper Networks Junos OS 19.3 versiones 19.3R1 y superiores anteriores a 19.3R2-S6, 19.3R3-S3; versiones 19.4 anteriores a 19.4R3-S5; versiones 20.1 anteriores a 20.1R2-S2, 20. 1R3-S1; versiones 20.2 anteriores a 20.2R3-S2; versiones 20.3 anteriores a 20.3R3; versiones 20.4 anteriores a 20.4R2-S1, 20.4R3; 21.1 versiones anteriores a 21.1R1-S1, 21.1R2. Este problema no afecta a Juniper Networks Junos OS versiones anteriores a 19.3R1"
    }
  ],
  "lastModified": "2026-06-17T03:29:41.450",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8110DA9-54B1-43CF-AACB-76EABE0C9EF6"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11B5CC5A-1959-4113-BFCF-E4BA63D918C1"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F08A33-EF80-4D86-9A9A-9DF147B9B6D3"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF24ACBD-5F84-47B2-BFF3-E9A56666269C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3935A586-41BD-4FA5-9596-DED6F0864777"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r2-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B83FB539-BD7C-4BEE-9022-098F73902F38"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r2-s4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7659AC36-A5EA-468A-9793-C1EC914D36F4"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r2-s5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0E018E1-568E-40F2-ADA5-F71509811879"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9295AF3-A883-47C3-BAF8-3D82F719733E"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F09D3262-394A-43D1-A4ED-8887FCB20F87"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.3:r3-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3FEA876-302D-4F07-94E6-237C669538F2"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC743EE4-8833-452A-94DB-655BF139F883"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE96A8EA-FFE3-4D8F-9266-21899149D634"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C12A75C6-2D00-4202-B861-00FF71585FA0"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r1-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70FF3DD4-14CB-435D-8529-0480EB853F60"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DCFA774-96EF-4018-82CF-95C807025C24"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76022948-4B07-43CB-824C-44E1AB3537CB"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25446F60-5CB9-4923-BCE8-609AE3CFDFBC"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r2-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A23E5CEA-EFF5-4641-BC47-BA2D0859F0EE"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "758275F3-9457-45A2-8F57-65DCD659FC1B"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B46CB928-78B5-4D60-B747-9A0988C7060D"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r3-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED73BF1A-96E4-49F1-A6AA-7B29DAA6C112"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r3-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0886EFA6-47E3-4C1D-A278-D3891A487FED"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:19.4:r3-s4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A209EE6F-E676-4172-8FF3-4E03748DEB13"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8328FDE6-9707-4142-B905-3B07C0E28E35"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41CD982F-E6F2-4951-9F96-A76C142DF08E"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19FDC05F-5582-4F7E-B628-E58A3C0E7F2F"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r1-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "401306D1-E9CE-49C6-8DC9-0E8747B9DC2C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r1-s4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "615EAF48-AD53-4CC2-B233-5EA5C0F72CB1"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC8E7547-6649-436D-BC45-184417680C72"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9789FF8-D55C-4AF9-A250-E543A0EB826F"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.1:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C21638A9-6AD8-4347-AA3F-64BC7BD71C0D"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD07B7E2-F5C2-4610-9133-FDA9E66DFF4F"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3C23AEB-34DE-44FB-8D64-E69D6E8B7401"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18DB9401-5A51-4BB3-AC2F-58F58F1C788C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r1-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06F53DA5-59AE-403C-9B1E-41CE267D8BB1"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3332262F-81DA-4D78-99C9-514CADA46611"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B46B63A2-1518-4A29-940C-F05624C9658D"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E0D4959-3865-42A7-98CD-1103EBD84528"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r2-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A58292B-814C-49E7-8D6D-BE26EFB9ADDF"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "681AE183-7183-46E7-82EA-28C398FA1C3D"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.2:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A6E9627-8BF1-4BE8-844B-EE8F1C9478F0"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.3:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C9BC697-C7C9-447D-9EBD-E9711462583E"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.3:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B80433B-57B1-49EF-B1A1-83781D6102E3"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.3:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05D8427C-CDDE-4B2F-9CB8-41B9137660E4"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.3:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3DC01F2-6DFE-4A8E-9962-5E59AA965935"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20DDC6B7-BFC4-4F0B-8E68-442C23765BF2"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "037BA01C-3F5C-4503-A633-71765E9EF774"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C54B047C-4B38-40C0-9855-067DCF7E48BD"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:21.1:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "625BA7E6-D2AD-4A48-9B94-24328BE5B06A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}