CVE-2023-28966: Juniper Junos OS Evolved
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modify existing files or execute commands as root. The issue is caused by improper file and directory permissions on certain system files, allowing an attacker with access to these files and folders to inject CLI commands as root. This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S5-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO.
Affected products
- Juniper Junos OS Evolved: before 20.4 (fixed in 20.4); version 20.4 only; version 21.2 only; version 21.3 only
Published 2023-04-17. Last modified 2026-06-17.