← Back

CVE-2024-21620

nvd nist
Published: Jan 25, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. A specific invocation of the emit_debug_note method in webauth_operation.php will echo back the data it receives. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S10; * 21.2 versions earlier than 21.2R3-S8; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3-S1; * 23.2 versions earlier than 23.2R2; * 23.4 versions earlier than 23.4R2.

Affected (89)

Products: Juniper: Junos
1 product
Junos
Configuration A
89 vulnerable · 104 platform
Vulnerable SoftwareAffected Versions
Juniper
Before 20.4
Version 20.4
Version 20.4 r1-s1
Version 20.4 r1
Version 20.4 r2-s1
Version 20.4 r2-s2
Version 20.4 r2
Version 20.4 r3-s1
Version 20.4 r3-s2
Version 20.4 r3-s3
Version 20.4 r3-s4
Version 20.4 r3-s5
Version 20.4 r3-s6
Version 20.4 r3-s7
Version 20.4 r3-s8
Version 20.4 r3-s9
Version 20.4 r3
Version 21.2
Version 21.2 r1-s1
Version 21.2 r1-s2
Version 21.2 r1
Version 21.2 r2-s1
Version 21.2 r2-s2
Version 21.2 r2
Version 21.2 r3-s1
Version 21.2 r3-s2
Version 21.2 r3-s3
Version 21.2 r3-s4
Version 21.2 r3-s5
Version 21.2 r3-s6
Version 21.2 r3-s7
Version 21.2 r3
Version 21.4
Version 21.4 r1-s1
Version 21.4 r1-s2
Version 21.4 r1
Version 21.4 r2-s1
Version 21.4 r2-s2
Version 21.4 r2
Version 21.4 r3-s1
Version 21.4 r3-s2
Version 21.4 r3-s3
Version 21.4 r3-s4
Version 21.4 r3-s5
Version 21.4 r3
Version 22.1
Version 22.1 r1-s1
Version 22.1 r1-s2
Version 22.1 r1
Version 22.1 r2-s1
Version 22.1 r2-s2
Version 22.1 r2
Version 22.1 r3-s1
Version 22.1 r3-s2
Version 22.1 r3-s3
Version 22.1 r3-s4
Version 22.1 r3
Version 22.2
Version 22.2 r1-s1
Version 22.2 r1-s2
Version 22.2 r1
Version 22.2 r2-s1
Version 22.2 r2-s2
Version 22.2 r2
Version 22.2 r3-s1
Version 22.2 r3-s2
Version 22.2 r3
Version 22.3
Version 22.3 r1-s1
Version 22.3 r1-s2
Version 22.3 r1
Version 22.3 r2-s1
Version 22.3 r2-s2
Version 22.3 r2
Version 22.3 r3-s1
Version 22.3 r3
Version 22.4
Version 22.4 r1-s1
Version 22.4 r1-s2
Version 22.4 r1
Version 22.4 r2-s1
Version 22.4 r2-s2
Version 22.4 r2
Version 22.4 r3
Version 23.2
Version 23.2 r1-s1
Version 23.2 r1-s2
Version 23.2 r1
Version 23.4 r1
Running on/withPlatform Versions
Juniper
Ex2200
All versions
Juniper
Ex2200 C
All versions
Juniper
Ex2200 Vc
All versions
Juniper
Ex2300
All versions
Juniper
Ex2300 24mp
All versions
Juniper
Ex2300 24p
All versions
Juniper
Ex2300 24t
All versions
Juniper
Ex2300 48mp
All versions
Juniper
Ex2300 48p
All versions
Juniper
Ex2300 48t
All versions
Juniper
Ex2300 C
All versions
Juniper
Ex2300 Multigigabit
All versions
Juniper
Ex2300m
All versions
Juniper
Ex3200
All versions
Juniper
Ex3300
All versions
Juniper
Ex3300 Vc
All versions
Juniper
Ex3400
All versions
Juniper
Ex4100
All versions
Juniper
Ex4100 F
All versions
Juniper
Ex4100 Multigigabit
All versions
Juniper
Ex4200
All versions
Juniper
Ex4200 Vc
All versions
Juniper
Ex4300
All versions
Juniper
Ex4300 24p
All versions
Juniper
Ex4300 24p S
All versions
Juniper
Ex4300 24t
All versions
Juniper
Ex4300 24t S
All versions
Juniper
Ex4300 32f
All versions
Juniper
Ex4300 32f Dc
All versions
Juniper
Ex4300 32f S
All versions
Juniper
Ex4300 48mp
All versions
Juniper
Ex4300 48mp S
All versions
Juniper
Ex4300 48p
All versions
Juniper
Ex4300 48p S
All versions
Juniper
Ex4300 48t
All versions
Juniper
Ex4300 48t Afi
All versions
Juniper
Ex4300 48t Dc
All versions
Juniper
Ex4300 48t Dc Afi
All versions
Juniper
Ex4300 48t S
All versions
Juniper
Ex4300 48tafi
All versions
Juniper
Ex4300 48tdc
All versions
Juniper
Ex4300 48tdc Afi
All versions
Juniper
Ex4300 Mp
All versions
Juniper
Ex4300 Vc
All versions
Juniper
Ex4300 Multigigabit
All versions
Juniper
Ex4300m
All versions
Juniper
Ex4400
All versions
Juniper
Ex4400 24x
All versions
Juniper
Ex4400 Multigigabit
All versions
Juniper
Ex4500
All versions
Juniper
Ex4500 Vc
All versions
Juniper
Ex4550
All versions
Juniper
Ex4550 Vc
All versions
Juniper
Ex4550/vc
All versions
Juniper
Ex4600
All versions
Juniper
Ex4600 Vc
All versions
Juniper
Ex4650
All versions
Juniper
Ex6200
All versions
Juniper
Ex6210
All versions
Juniper
Ex8200
All versions
Juniper
Ex8200 Vc
All versions
Juniper
Ex8208
All versions
Juniper
Ex8216
All versions
Juniper
Ex9200
All versions
Juniper
Ex9204
All versions
Juniper
Ex9208
All versions
Juniper
Ex9214
All versions
Juniper
Ex9250
All versions
Juniper
Ex9251
All versions
Juniper
Ex9253
All versions
Juniper
Ex Redundant Power System
All versions
Juniper
Ex Rps
All versions
Juniper
Srx100
All versions
Juniper
Srx110
All versions
Juniper
Srx1400
All versions
Juniper
Srx1500
All versions
Juniper
Srx1600
All versions
Juniper
Srx210
All versions
Juniper
Srx220
All versions
Juniper
Srx2300
All versions
Juniper
Srx240
All versions
Juniper
Srx240h2
All versions
Juniper
Srx240m
All versions
Juniper
Srx300
All versions
Juniper
Srx320
All versions
Juniper
Srx340
All versions
Juniper
Srx3400
All versions
Juniper
Srx345
All versions
Juniper
Srx3600
All versions
Juniper
Srx380
All versions
Juniper
Srx4000
All versions
Juniper
Srx4100
All versions
Juniper
Srx4200
All versions
Juniper
Srx4300
All versions
Juniper
Srx4600
All versions
Juniper
Srx4700
All versions
Juniper
Srx5000
All versions
Juniper
Srx5400
All versions
Juniper
Srx550
All versions
Juniper
Srx550 Hm
All versions
Juniper
Srx550m
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions
Juniper
Srx650
All versions

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.