CVE-2021-31357

Description

A command injection vulnerability in tcpdump command processing on Junos OS Evolved Evolved allows an attacker with authenticated CLI access to bypass configured access protections to execute arbitrary shell commands within the context of the current user.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.217

Associated Vulnerability

VulnerabilityOS Platform
Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability (CVE-2021-31357)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234