QID 43928
Date Published: 2022-10-20
QID 43928: Juniper Network Operating System (Junos OS) Cross-Site Scripting (XSS) Vulnerability (JSA69519)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator.
Affected Junos versions:
12.3 versions prior to 12.3R12-S19
15.1 versions prior to 15.1R7-S10
18.3 versions prior to 18.3R3-S5
18.4 versions prior to 18.4R2-S10, 18.4R3-S9
19.1 versions prior to 19.1R2-S3, 19.1R3-S6
19.2 versions prior to 19.2R1-S8, 19.2R3-S3
19.3 versions prior to 19.3R2-S6, 19.3R3-S3
19.4 versions prior to 19.4R3-S5
20.1 versions prior to 20.1R3-S2
20.2 versions prior to 20.2R3-S2
20.3 versions prior to 20.3R3
20.4 versions prior to 20.4R2-S2, 20.4R3
21.1 versions prior to 21.1R1-S1, 21.1R2
21.2 versions prior to 21.2R1-S1, 21.2R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS versions and If the HTTP and HTTPS services are disabled then, QID will not be flagged.
Successful exploitation of this vulnerability may allow an attacker to execute commands with target permissions by forcing victim to click malicious link.
Workaround:
To reduce the risk of exploitation of this issue, use access lists or firewall filters to limit access to only trusted administrative networks, hosts and users. Alternatively, J-Web can be disabled.
- JSA69519 -
kb.juniper.net/JSA69519
CVEs related to QID 43928
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA69519 |
|