Juniper Networks Release Security Updates for Junos OS
Out-of-cycle security updates address multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS
Summary
Out-of-cycle security updates address multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Juniper Networks has issued a security bulletin addressing four vulnerabilities in the J-Web component of Junos OS SRX Series and EX Series. A Cross Site Scripting vulnerability, CVE-2024-21620, has a CVSSv3 score of 8.8 and could allow an attacker to construct a URL that, when visited by another user, enables the attacker to execute commands with the target's permissions, including as administrator.
Remediation advice
Affected organisations are encouraged to review the Juniper Junos OS Security Bulletin and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 30 January 2024 3:31 pm