Vulnerability Description
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ability to resume a previous interactive session and possibly gain administrative privileges. This issue affects all Juniper Networks Junos OS Evolved versions after 18.4R1-EVO, prior to 20.2R1-EVO.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos Os Evolved | 19.2 |
Related Weaknesses (CWE)
References
- https://kb.juniper.net/JSA11063Vendor Advisory
- https://kb.juniper.net/JSA11063Vendor Advisory
FAQ
What is CVE-2020-1666?
CVE-2020-1666 is a vulnerability with a CVSS score of 6.6 (MEDIUM). The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a m...
How severe is CVE-2020-1666?
CVE-2020-1666 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1666?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos Os Evolved.