← Back

CVE-2021-31384

nvd nist
Published: Oct 19, 2021Modified: Jun 17, 2026

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.

Affected (4)

Products: Juniper: Junos
1 product
Junos
Configuration A
4 vulnerable · 9 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 20.4 r1-s1
Version 20.4 r1
Version 20.4 r2
Version 21.1 r1
Running on/withPlatform Versions
Juniper
Srx1500
All versions
Juniper
Srx300
All versions
Juniper
Srx4100
All versions
Juniper
Srx4200
All versions
Juniper
Srx4600
All versions
Juniper
Srx5400
All versions
Juniper
Srx550
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions

References (3)

Source: sirt@juniper.net
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.