Database/Firmware, BMC & network fabric
Juniper Junos OS / Junos OS Evolved (annotate configuration command): The `annotate` configuration command can be used
Impact
The annotate configuration command can be used to escalate privileges. A user with limited configuration rights — the sort of account you give an automation system or a junior operator — gains more than their class allows on a device that may be a spine. Junos login classes are the mechanism most Juniper shops use for internal separation of duties, and this puts a hole in it.
Who can reach it
Authenticated low-privileged user with configuration access to the device.
What to do
Junos upgrade plus reboot. Interim: restrict the annotate command in affected login classes via the allow-/deny-commands regex — a live config change that closes it without a maintenance window.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.