A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Junip
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to
webauth_operation.php
that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of
integrity or confidentiality, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on SRX Series:
21.2 versions prior to 21.2R3-S8;
versions prior to
21.4R3-S6;
versions prior to
22.1R3-S5;
versions prior to
22.2R3-S3;
versions prior to
22.3R3-S2;
23.2R1-S2, 23.2R2.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 53.00 |
| 利用信号(KEV 收录) | ×1.50 |
| VPI | 79.50 |
VPI 公式 vpi-v1
必要措施
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.