Skip to main content

Juniper Networks Release Security Updates for Junos OS

Out-of-cycle security updates address multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Out-of-cycle security updates address multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS


Threat details

Introduction

Juniper Networks has issued a security bulletin addressing four vulnerabilities in the J-Web component of Junos OS SRX Series and EX Series. A Cross Site Scripting vulnerability, CVE-2024-21620, has a CVSSv3 score of 8.8 and could allow an attacker to construct a URL that, when visited by another user, enables the attacker to execute commands with the target's permissions, including as administrator. 


Remediation advice

Affected organisations are encouraged to review the Juniper Junos OS Security Bulletin and apply any relevant updates.



CVE Vulnerabilities

Last edited: 30 January 2024 3:31 pm