An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource.
This vulnerability allows any low-privileged user logged into the system to connect to the Unix socket and issue commands to manage the DHCP service, in essence, taking administrative control of the local DHCP server or DHCP relay.
This issue affects: Junos OS:
Junos OS Evolved:
| Software | From | Fixed in |
|---|---|---|
| juniper / junos | - | 21.2 |
| juniper / junos | 21.2 | 21.2.x |
| juniper / junos | 21.2-r1 | 21.2-r1.x |
| juniper / junos | 21.2-r1-s1 | 21.2-r1-s1.x |
| juniper / junos | 21.2-r1-s2 | 21.2-r1-s2.x |
| juniper / junos | 21.2-r2 | 21.2-r2.x |
| juniper / junos | 21.2-r2-s1 | 21.2-r2-s1.x |
| juniper / junos | 21.2-r2-s2 | 21.2-r2-s2.x |
| juniper / junos | 21.2-r3 | 21.2-r3.x |
| juniper / junos | 21.2-r3-s1 | 21.2-r3-s1.x |
| juniper / junos | 21.2-r3-s2 | 21.2-r3-s2.x |
| juniper / junos | 21.2-r3-s3 | 21.2-r3-s3.x |
| juniper / junos | 21.2-r3-s4 | 21.2-r3-s4.x |
| juniper / junos | 21.2-r3-s5 | 21.2-r3-s5.x |
| juniper / junos | 21.2-r3-s6 | 21.2-r3-s6.x |
| juniper / junos | 21.2-r3-s7 | 21.2-r3-s7.x |
| juniper / junos | 21.2-r3-s8 | 21.2-r3-s8.x |
| juniper / junos | 21.2-r3-s9 | 21.2-r3-s9.x |
| juniper / junos | 21.4 | 21.4.x |
| juniper / junos | 21.4-r1 | 21.4-r1.x |
| juniper / junos | 21.4-r1-s1 | 21.4-r1-s1.x |
| juniper / junos | 21.4-r1-s2 | 21.4-r1-s2.x |
| juniper / junos | 21.4-r2 | 21.4-r2.x |
| juniper / junos | 21.4-r2-s1 | 21.4-r2-s1.x |
| juniper / junos | 21.4-r2-s2 | 21.4-r2-s2.x |
| juniper / junos | 21.4-r3 | 21.4-r3.x |
| juniper / junos | 21.4-r3-s1 | 21.4-r3-s1.x |
| juniper / junos | 21.4-r3-s10 | 21.4-r3-s10.x |
| juniper / junos | 21.4-r3-s11 | 21.4-r3-s11.x |
| juniper / junos | 21.4-r3-s2 | 21.4-r3-s2.x |
| juniper / junos | 21.4-r3-s3 | 21.4-r3-s3.x |
| juniper / junos | 21.4-r3-s4 | 21.4-r3-s4.x |
| juniper / junos | 21.4-r3-s5 | 21.4-r3-s5.x |
| juniper / junos | 21.4-r3-s6 | 21.4-r3-s6.x |
| juniper / junos | 21.4-r3-s7 | 21.4-r3-s7.x |
| juniper / junos | 21.4-r3-s8 | 21.4-r3-s8.x |
| juniper / junos | 21.4-r3-s9 | 21.4-r3-s9.x |
| juniper / junos | 22.2 | 22.2.x |
| juniper / junos | 22.4 | 22.4.x |
| juniper / junos | 22.4-r1 | 22.4-r1.x |
| juniper / junos | 22.4-r1-s1 | 22.4-r1-s1.x |
| juniper / junos | 22.4-r1-s2 | 22.4-r1-s2.x |
| juniper / junos | 22.4-r2 | 22.4-r2.x |
| juniper / junos | 22.4-r2-s1 | 22.4-r2-s1.x |
| juniper / junos | 22.4-r2-s2 | 22.4-r2-s2.x |
| juniper / junos | 22.4-r3 | 22.4-r3.x |
| juniper / junos | 22.4-r3-s1 | 22.4-r3-s1.x |
| juniper / junos | 22.4-r3-s2 | 22.4-r3-s2.x |
| juniper / junos | 22.4-r3-s3 | 22.4-r3-s3.x |
| juniper / junos | 22.4-r3-s4 | 22.4-r3-s4.x |
| juniper / junos | 22.4-r3-s5 | 22.4-r3-s5.x |
| juniper / junos | 22.4-r3-s6 | 22.4-r3-s6.x |
| juniper / junos | 22.4-r3-s7 | 22.4-r3-s7.x |
| juniper / junos | 23.2 | 23.2.x |
| juniper / junos | 23.2-r1 | 23.2-r1.x |
| juniper / junos | 23.2-r1-s1 | 23.2-r1-s1.x |
| juniper / junos | 23.2-r1-s2 | 23.2-r1-s2.x |
| juniper / junos | 23.2-r2 | 23.2-r2.x |
| juniper / junos | 23.2-r2-s1 | 23.2-r2-s1.x |
| juniper / junos | 23.2-r2-s2 | 23.2-r2-s2.x |
| juniper / junos | 23.2-r2-s3 | 23.2-r2-s3.x |
| juniper / junos | 23.2-r2-s4 | 23.2-r2-s4.x |
| juniper / junos | 23.4 | 23.4.x |
| juniper / junos | 23.4-r1 | 23.4-r1.x |
| juniper / junos | 23.4-r1-s1 | 23.4-r1-s1.x |
| juniper / junos | 23.4-r1-s2 | 23.4-r1-s2.x |
| juniper / junos | 23.4-r2 | 23.4-r2.x |
| juniper / junos | 23.4-r2-s1 | 23.4-r2-s1.x |
| juniper / junos | 23.4-r2-s2 | 23.4-r2-s2.x |
| juniper / junos | 23.4-r2-s3 | 23.4-r2-s3.x |
| juniper / junos | 23.4-r2-s4 | 23.4-r2-s4.x |
| juniper / junos | 23.4-r2-s5 | 23.4-r2-s5.x |
| juniper / junos | 24.2 | 24.2.x |
| juniper / junos | 24.2-r1 | 24.2-r1.x |
| juniper / junos | 24.2-r1-s1 | 24.2-r1-s1.x |
| juniper / junos | 24.2-r1-s2 | 24.2-r1-s2.x |
| juniper / junos | 24.2-r2 | 24.2-r2.x |
| juniper / junos | 24.2-r2-s1 | 24.2-r2-s1.x |
| juniper / junos | 24.4 | 24.4.x |
| juniper / junos | 24.4-r1 | 24.4-r1.x |
| juniper / junos | 24.4-r1-s2 | 24.4-r1-s2.x |
| juniper / junos | 24.4-r1-s3 | 24.4-r1-s3.x |
| juniper / junos | 25.2 | 25.2.x |
| juniper / junos | 25.2-r1 | 25.2-r1.x |
| juniper / junos | 25.2-r2 | 25.2-r2.x |
| juniper / junos_os_evolved | - | 22.4 |
| juniper / junos_os_evolved | 22.4 | 22.4.x |
| juniper / junos_os_evolved | 22.4-r1 | 22.4-r1.x |
| juniper / junos_os_evolved | 22.4-r1-s1 | 22.4-r1-s1.x |
| juniper / junos_os_evolved | 22.4-r1-s2 | 22.4-r1-s2.x |
| juniper / junos_os_evolved | 22.4-r2 | 22.4-r2.x |
| juniper / junos_os_evolved | 22.4-r2-s1 | 22.4-r2-s1.x |
| juniper / junos_os_evolved | 22.4-r2-s2 | 22.4-r2-s2.x |
| juniper / junos_os_evolved | 22.4-r3 | 22.4-r3.x |
| juniper / junos_os_evolved | 22.4-r3-s1 | 22.4-r3-s1.x |
| juniper / junos_os_evolved | 22.4-r3-s2 | 22.4-r3-s2.x |
| juniper / junos_os_evolved | 22.4-r3-s3 | 22.4-r3-s3.x |
| juniper / junos_os_evolved | 22.4-r3-s4 | 22.4-r3-s4.x |
| juniper / junos_os_evolved | 22.4-r3-s5 | 22.4-r3-s5.x |
| juniper / junos_os_evolved | 22.4-r3-s6 | 22.4-r3-s6.x |
| juniper / junos_os_evolved | 22.4-r3-s7 | 22.4-r3-s7.x |
| juniper / junos_os_evolved | 23.2 | 23.2.x |
| juniper / junos_os_evolved | 23.2-r1 | 23.2-r1.x |
| juniper / junos_os_evolved | 23.2-r1-s1 | 23.2-r1-s1.x |
| juniper / junos_os_evolved | 23.2-r1-s2 | 23.2-r1-s2.x |
| juniper / junos_os_evolved | 23.2-r2 | 23.2-r2.x |
| juniper / junos_os_evolved | 23.2-r2-s1 | 23.2-r2-s1.x |
| juniper / junos_os_evolved | 23.2-r2-s2 | 23.2-r2-s2.x |
| juniper / junos_os_evolved | 23.2-r2-s3 | 23.2-r2-s3.x |
| juniper / junos_os_evolved | 23.2-r2-s4 | 23.2-r2-s4.x |
| juniper / junos_os_evolved | 23.4 | 23.4.x |
| juniper / junos_os_evolved | 23.4-r1 | 23.4-r1.x |
| juniper / junos_os_evolved | 23.4-r1-s1 | 23.4-r1-s1.x |
| juniper / junos_os_evolved | 23.4-r1-s2 | 23.4-r1-s2.x |
| juniper / junos_os_evolved | 23.4-r2 | 23.4-r2.x |
| juniper / junos_os_evolved | 23.4-r2-s1 | 23.4-r2-s1.x |
| juniper / junos_os_evolved | 23.4-r2-s2 | 23.4-r2-s2.x |
| juniper / junos_os_evolved | 23.4-r2-s3 | 23.4-r2-s3.x |
| juniper / junos_os_evolved | 23.4-r2-s4 | 23.4-r2-s4.x |
| juniper / junos_os_evolved | 23.4-r2-s5 | 23.4-r2-s5.x |
| juniper / junos_os_evolved | 24.2 | 24.2.x |
| juniper / junos_os_evolved | 24.2-r1 | 24.2-r1.x |
| juniper / junos_os_evolved | 24.2-r1-s2 | 24.2-r1-s2.x |
| juniper / junos_os_evolved | 24.2-r2 | 24.2-r2.x |
| juniper / junos_os_evolved | 24.2-r2-s1 | 24.2-r2-s1.x |
| juniper / junos_os_evolved | 24.4 | 24.4.x |
| juniper / junos_os_evolved | 24.4-r1 | 24.4-r1.x |
| juniper / junos_os_evolved | 24.4-r1-s2 | 24.4-r1-s2.x |
| juniper / junos_os_evolved | 24.4-r1-s3 | 24.4-r1-s3.x |
| juniper / junos_os_evolved | 25.2 | 25.2.x |
| juniper / junos_os_evolved | 25.2-r1 | 25.2-r1.x |
| juniper / junos_os_evolved | 25.2-r2 | 25.2-r2.x |