Juniper Networks Releases Urgent Junos OS Updates for High
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-36846 | Unauthenticated File Upload in Juniper Junos OS SRX J-Web Chainable to RCE CVE-2023-36846 is a Missing Authentication for Critical Function flaw (CWE-306) in the J-Web web-management interface of Juniper Networks Junos OS running on SRX Series firewalls: a specific unauthenticated request to user.php allows an attacker to upload arbitrary files. Successful uploads compromise the integrity of part of the file system and can be chained with other recently disclosed Juniper J-Web vulnerabilities to achieve full unauthenticated remote code execution. Any SRX Series device running an affected Junos OS release with J-Web reachable over the network is affected; Juniper issued out-of-band fixes and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-13 with a federal patch deadline of November 17. Exploitation is confirmed in the wild, as threat actors began attacking the Juniper J-Web flaws shortly after public PoC code was released, and EPSS assigns a ~95% probability of exploitation within 30 days. Internet-wide scans identified nearly 12,000 vulnerable Juniper firewalls exposed, indicating exposure concentrated on internet-facing edge devices. Do: Upgrade affected SRX Series devices to a fixed Junos OS release: 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2 or 22.3R3, or 22.4R2-S1 or 22.4R3 (devices on 21.1 must move to a later supported release). Until patching, disable J-Web or restrict it to trusted management networks, and verify devices for compromise since in-the-wild exploitation and CISA KEV listing (federal deadline November 17) are already in effect. | 5.3 | 95% | KEV |
| large~12,000 internet-exposed Juniper SRX firewalls (public scan of the related J-Web RCE); total SRX install base likely larger | |
| CVE-2023-36851 | Unauthenticated Arbitrary File Upload/Download in Juniper SRX Series J-Web This is a missing-authentication flaw (CWE-306) in the J-Web web management interface of Juniper Networks Junos OS running on SRX Series firewalls. An unauthenticated, network-based attacker can send a crafted request to webauth_operation.php, which requires no authentication, and upload or download arbitrary files on the device. The result is limited loss of file system integrity and potential loss of confidentiality, and the file access may be chained with other vulnerabilities to increase impact. Any organization running an affected Junos OS release on an SRX Series device with J-Web enabled is affected, especially where that interface is reachable from untrusted networks. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2023-11-13 as one of five Juniper flaws and set a patch deadline of November 17, 2023. Do: Upgrade affected SRX Series devices to the fixed releases: 21.2R3-S8, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2 or 22.4R3, or 23.2R1-S2 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict it to trusted management networks and interfaces only. Review device logs for unauthenticated requests to webauth_operation.php as evidence of exploitation, and prioritize patching given the CISA KEV deadline of November 17, 2023. | 5.3 | 1% | KEV |
| largetens of thousands of internet-exposed SRX firewalls with J-Web enabled (a subset of a very large installed base) | |
| CVE-2024-21591 | An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to caus An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory. This issue affects Juniper Networks Junos OS SRX Series and EX Series: * Junos OS versions earlier than 20.4R3-S9; * Junos OS 21.2 versions earlier than 21.2R3-S7; * Junos OS 21.3 versions earlier than 21.3R3-S5; * Junos OS 21.4 versions earlier than 21.4R3-S5; * Junos OS 22.1 versions earlier than 22.1R3-S4; * Junos OS 22.2 versions earlier than 22.2R3-S3; * Junos OS 22.3 versions earlier than 22.3R3-S2; * Junos OS 22.4 versions earlier than 22.4R2-S2, 22.4R3. NVD description · AI analysis pending | 9.8 | 18% | PoC |
| — | |
| CVE-2024-21619 +1 in the same advisory: …21620 | A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S7; * 21.3 versions earlier than 21.3R3-S5; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R1-S2, 23.2R2. NVD description · AI analysis pending | 7.5 group max | <1% |
| — |
Full article303 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 30, 2024Vulnerability / Network Security
Juniper Networks has released out-of-band updates to address high-severity flaws in SRX Series and EX Series that could be exploited by a threat actor to take control of susceptible systems.
The vulnerabilities, tracked as CVE-2024-21619 and CVE-2024-21620, are rooted in the J-Web component and impact all versions of Junos OS. Two other shortcomings, CVE-2023-36846 and CVE-2023-36851, were previously disclosed by the company in August 2023.
- CVE-2024-21619 (CVSS score: 5.3) - A missing authentication vulnerability that could lead to exposure of sensitive configuration information
- CVE-2024-21620 (CVSS score: 8.8) - A cross-site scripting (XSS) vulnerability that could lead to the execution of arbitrary commands with the target's permissions by means of a specially crafted request
Cybersecurity firm watchTowr Labs has been credited with discovering and reporting the issues. The two vulnerabilities have been addressed in the following versions -
- CVE-2024-21619 - 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases
- CVE-2024-21620 - 20.4R3-S10, 21.2R3-S8, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R3-S1, 23.2R2, 23.4R2, and all subsequent releases
As temporary mitigations until the fixes are deployed, the company is recommending that users disable J-Web or restrict access to only trusted hosts.
It's worth noting that both CVE-2023-36846 and CVE-2023-36851 were added to the Known Exploited Vulnerabilities (KEV) catalog in November 2023 by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), based on evidence of active exploitation.
Earlier this month, Juniper Networks also shipped fixes to contain a critical vulnerability in the same products (CVE-2024-21591, CVSS score: 9.8) that could enable an attacker to cause a denial-of-service (DoS) or remote code execution and obtain root privileges on the devices.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/01/juniper-networks-releases-urgent-junos.html