The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ability to resume a previous interactive session and possibly gain administrative privileges. This issue affects all Juniper Networks Junos OS Evolved versions after 18.4R1-EVO, prior to 20.2R1-EVO.
2020-10-16T21:15:12.677
2024-11-21T05:11:07.070
Modified
CVSSv3.1: 6.6 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | juniper | junos_os_evolved | 19.2 | Yes |
Operating System | juniper | junos_os_evolved | 19.2 | Yes |
Operating System | juniper | junos_os_evolved | 19.3 | Yes |
Operating System | juniper | junos_os_evolved | 19.4 | Yes |
Operating System | juniper | junos_os_evolved | 19.4 | Yes |
Operating System | juniper | junos_os_evolved | 19.4 | Yes |
Operating System | juniper | junos_os_evolved | 20.1 | Yes |