Impact
The vulnerability in the Juniper Networks Support Insights Virtual Lightweight Collector CLI allows a local high privileged attacker to run arbitrary shell commands with root permissions. This shell command injection leads to full control of the system, compromising confidentiality, integrity, and availability. The weakness is an improper restriction of operations within a command, as identified by CWE‑183.
Affected Systems
Juniper Networks JSI Virtual Lightweight Collector (vLWC) is affected. All versions earlier than 3.0.94 are vulnerable; subsequent releases have been updated to fix the issue.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers need local, high‑privilege access and can exploit the vulnerability through the CLI, sending crafted input that is executed with root privileges. The attack vector is inferred to be local due to the requirement for CLI access.
OpenCVE Enrichment