← Back

CVE-2024-39565

nvd nist
Published: Jul 10, 2024Modified: Jan 22, 2026

JSON object

Loading...
7.7
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:M/U:Amber
Show more
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:M/U:AmberShow less
Source: sirt@juniper.net (Secondary)

Description

An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device.  While an administrator is logged into a J-Web session or has previously logged in and subsequently logged out of their J-Web session, the attacker can arbitrarily execute commands on the target device with the other user's credentials. In the worst case, the attacker will have full control over the device. This issue affects Junos OS:  * All versions before 21.2R3-S8,  * from 21.4 before 21.4R3-S7, * from 22.2 before 22.2R3-S4, * from 22.3 before 22.3R3-S3, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2, * from 23.4 before 23.4R1-S1, 23.4R2.

Affected (68)

Products: Juniper: J Web, Junos
2 products
J Web
Junos
Configuration A
68 vulnerable · 31 platform
Vulnerable SoftwareAffected Versions
All versions
Juniper
Before 21.2
Version 21.2
Version 21.2 r1-s1
Version 21.2 r1-s2
Version 21.2 r1
Version 21.2 r2-s1
Version 21.2 r2-s2
Version 21.2 r2
Version 21.2 r3-s1
Version 21.2 r3-s2
Version 21.2 r3-s3
Version 21.2 r3-s4
Version 21.2 r3-s5
Version 21.2 r3-s6
Version 21.2 r3-s7
Version 21.2 r3
Version 21.4
Version 21.4 r1-s1
Version 21.4 r1-s2
Version 21.4 r1
Version 21.4 r2-s1
Version 21.4 r2-s2
Version 21.4 r2
Version 21.4 r3-s1
Version 21.4 r3-s2
Version 21.4 r3-s3
Version 21.4 r3-s4
Version 21.4 r3-s5
Version 21.4 r3-s6
Version 21.4 r3
Version 22.2
Version 22.2 r1-s1
Version 22.2 r1-s2
Version 22.2 r1
Version 22.2 r2-s1
Version 22.2 r2-s2
Version 22.2 r2
Version 22.2 r3-s1
Version 22.2 r3-s2
Version 22.2 r3-s3
Version 22.2 r3
Version 22.3
Version 22.3 r1-s1
Version 22.3 r1-s2
Version 22.3 r1
Version 22.3 r2-s1
Version 22.3 r2-s2
Version 22.3 r2
Version 22.3 r3-s1
Version 22.3 r3-s2
Version 22.3 r3
Version 22.4
Version 22.4 r1-s1
Version 22.4 r1-s2
Version 22.4 r1
Version 22.4 r2-s1
Version 22.4 r2-s2
Version 22.4 r2
Version 22.4 r3-s1
Version 22.4 r3
Version 23.2
Version 23.2 r1-s1
Version 23.2 r1-s2
Version 23.2 r1
Version 23.4
Version 23.4 r1
Version 23.4 r2
Running on/withPlatform Versions
Juniper
Ex2300
All versions
Juniper
Ex2300 C
All versions
Juniper
Ex3400
All versions
Juniper
Ex4000
All versions
Juniper
Ex4100
All versions
Juniper
Ex4100 F
All versions
Juniper
Ex4100 H
All versions
Juniper
Ex4300
All versions
Juniper
Ex4400
All versions
Juniper
Ex4600
All versions
Juniper
Ex4650
All versions
Juniper
Ex9204
All versions
Juniper
Ex9208
All versions
Juniper
Ex9214
All versions
Juniper
Srx1500
All versions
Juniper
Srx1600
All versions
Juniper
Srx2300
All versions
Juniper
Srx300
All versions
Juniper
Srx320
All versions
Juniper
Srx340
All versions
Juniper
Srx345
All versions
Juniper
Srx380
All versions
Juniper
Srx4100
All versions
Juniper
Srx4120
All versions
Juniper
Srx4200
All versions
Juniper
Srx4300
All versions
Juniper
Srx4600
All versions
Juniper
Srx4700
All versions
Juniper
Srx5400
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions

Timeline

No history available yet.