CVE-2025-60006
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands.
When an attacker executes crafted CLI commands, the options are processed via a script in some cases. These scripts are not hardened so injected commands might be executed via the shell, which allows an attacker to perform operations, which they should not be able to do according to their assigned permissions.
This issue affects Junos OS Evolved:
This issue does not affect Junos OS Evolved versions earlier than 24.2R1-EVO.
Detalles técnicos trazas, registros y código del informe original
* 24.2 versions before 24.2R2-S2-EVO, * 24.4 versions before 24.4R2-EVO.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.99%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-60006",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-60006",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-10-10T03:55:27.325232Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 1.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 4.8,
"Automatable": "YES",
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "LOW",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "sirt@juniper.net",
"affectedData": [
{
"vendor": "Juniper Networks",
"product": "Junos OS Evolved",
"versions": [
{
"status": "affected",
"version": "24.2",
"lessThan": "24.2R2-S2-EVO",
"versionType": "semver"
},
{
"status": "affected",
"version": "24.4",
"lessThan": "24.4R2-EVO",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "24.2R1",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-10-09T17:16:03.857",
"references": [
{
"url": "https://supportportal.juniper.net/JSA103163",
"tags": [
"Vendor Advisory"
],
"source": "sirt@juniper.net"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') \n\nvulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands.\n\nWhen an attacker executes crafted CLI commands, the options are processed via a script in some cases. These scripts are not hardened so injected commands might be executed via the shell, which allows an attacker to perform operations, which they should not be able to do according to their assigned permissions.\n\nThis issue affects Junos OS Evolved:\n\n\n\n * 24.2 versions before 24.2R2-S2-EVO,\n * 24.4 versions before 24.4R2-EVO.\n\n\n\n\nThis issue does not affect Junos OS Evolved versions earlier than 24.2R1-EVO."
},
{
"lang": "es",
"value": "Múltiples instancias de una Neutralización Incorrecta de Elementos Especiales utilizados en un Comando de SO ('Inyección de Comandos de SO') vulnerabilidad en la CLI de Juniper Networks Junos OS Evolved podría usarse para elevar privilegios y/o ejecutar comandos no autorizados.\n\nCuando un atacante ejecuta comandos CLI manipulados, las opciones se procesan a través de un script en algunos casos. Estos scripts no están reforzados por lo que los comandos inyectados podrían ejecutarse a través del shell, lo que permite a un atacante realizar operaciones que no deberían poder hacer según sus permisos asignados.\n\nEste problema afecta a Junos OS Evolved:\n\n* versiones 24.2 anteriores a 24.2R2-S2-EVO,\n* versiones 24.4 anteriores a 24.4R2-EVO.\n\nEste problema no afecta a las versiones de Junos OS Evolved anteriores a 24.2R1-EVO."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DD89AAD-C615-42AF-B8AF-E6067862F0F5"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.2:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28AFF11D-E418-4A76-B557-F60622602537"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.2:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A86A69D-2B90-4B3B-A6EC-88358284787D"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.2:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "080BEA58-9667-4C2C-810D-DC1187DB67DA"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.2:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34072A94-CFEB-4FAA-8E68-E98D4F7602E4"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B32ADA05-5F5D-45B6-BB7B-3FA6A6F229F5"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6526E82-A6A6-4A65-9B01-B3FCB947F44E"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF3B74FA-DF84-4E3E-BCF9-44EEF9E45910"
},
{
"criteria": "cpe:2.3:o:juniper:junos_os_evolved:24.4:r1-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC024CDE-DA63-4E87-BA97-5E8C06B0D8B7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "sirt@juniper.net"
}