CVE-2024-39565
7.7
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:M/U:AmberShow more
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:M/U:AmberShow less
Source: sirt@juniper.net (Secondary)
Description
An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device.
While an administrator is logged into a J-Web session or has previously logged in and subsequently logged out of their J-Web session, the attacker can arbitrarily execute commands on the target device with the other user's credentials. In the worst case, the attacker will have full control over the device.
This issue affects Junos OS:
* All versions before 21.2R3-S8,
* from 21.4 before 21.4R3-S7,
* from 22.2 before 22.2R3-S4,
* from 22.3 before 22.3R3-S3,
* from 22.4 before 22.4R3-S2,
* from 23.2 before 23.2R2,
* from 23.4 before 23.4R1-S1, 23.4R2.
Affected (68)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Before 21.2 |
| Running on/with | Platform Versions |
|---|---|
Juniper Ex2300 | All versions |
Juniper Ex2300 C | All versions |
Juniper Ex3400 | All versions |
Juniper Ex4000 | All versions |
Juniper Ex4100 | All versions |
Juniper Ex4100 F | All versions |
Juniper Ex4100 H | All versions |
Juniper Ex4300 | All versions |
Juniper Ex4400 | All versions |
Juniper Ex4600 | All versions |
Juniper Ex4650 | All versions |
Juniper Ex9204 | All versions |
Juniper Ex9208 | All versions |
Juniper Ex9214 | All versions |
Juniper Srx1500 | All versions |
Juniper Srx1600 | All versions |
Juniper Srx2300 | All versions |
Juniper Srx300 | All versions |
Juniper Srx320 | All versions |
Juniper Srx340 | All versions |
Juniper Srx345 | All versions |
Juniper Srx380 | All versions |
Juniper Srx4100 | All versions |
Juniper Srx4120 | All versions |
Juniper Srx4200 | All versions |
Juniper Srx4300 | All versions |
Juniper Srx4600 | All versions |
Juniper Srx4700 | All versions |
Juniper Srx5400 | All versions |
Juniper Srx5600 | All versions |
Juniper Srx5800 | All versions |
References (6)
Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchProduct
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.