CVE-2021-31349
Summary
| CVE | CVE-2021-31349 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-19 19:15:00 UTC |
| Updated | 2022-10-25 15:32:00 UTC |
| Description | The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Juniper | 128 Technology Session Smart Router | - | All | All | All |
| Operating System | Juniper | 128 Technology Session Smart Router Firmware | All | All | All | All |
| Operating System | Juniper | 128 Technology Session Smart Router Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2021-10 Security Bulletin: Session Smart Router: Authentication Bypass Vulnerability (CVE-2021-31349) - Juniper Networks | CONFIRM | kb.juniper.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: 128 Technology was notified via the JVN community of the vulnerability as JVN#85073657.
There are currently no legacy QID mappings associated with this CVE.