KEVIntel
6.7
CVSS
Medium

CVE-2025-21590

PUBLISHED

Junos OS: An local attacker with shell access can execute arbitrary code

Exploited in the wild Low complexity No user interaction
Vendor
Juniper Networks
Product
Junos OS
Published
Mar 12, 2025
EPSS

Description

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device. This issue is not exploitable from the Junos CLI. This issue affects Junos OS:  * All versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10,  * 22.2 versions before 22.2R3-S6,  * 22.4 versions before 22.4R3-S6,  * 23.2 versions before 23.2R2-S3,  * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R1-S2, 24.2R2.

cisa edge nessus_scanner

CVSS scores

CVSS v4.0 6.7 Medium

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

CVSS v3.1 4.4 Medium

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Exploitation status

Exploited in the wild

Recorded 2025-03-13 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 13, 2025

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/232834 Jun 02, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus