An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the device to get access to a user account.
When the console cable is disconnected, the logged in user is not logged out. This allows a malicious attacker with physical access to the console to resume a previous session and possibly gain administrative privileges.
This issue affects Junos OS Evolved:
| Software | From | Fixed in |
|---|---|---|
| juniper / junos_os_evolved | 23.4-r1-s1 | 23.4-r1-s1.x |
| juniper / junos_os_evolved | 23.4-r1 | 23.4-r1.x |
| juniper / junos_os_evolved | 23.2-r2 | 23.2-r2.x |
| juniper / junos_os_evolved | 23.4-r1-s2 | 23.4-r1-s2.x |