QID 43929
Date Published: 2022-10-20
QID 43929: Juniper Network Operating System (Junos OS) Cross-Site Scripting (XSS) Vulnerability (JSA69517)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web.
Affected Junos versions:
All versions prior to 18.3R3-S5
18.4 versions prior to 18.4R3-S9
19.1 versions prior to 19.1R3-S6
19.2 versions prior to 19.2R3-S3
19.3 versions prior to 19.3R2-S6, 19.3R3-S3
19.4 versions prior to 19.4R3-S5
20.1 versions prior to 20.1R3-S4
20.2 versions prior to 20.2R3-S2
20.3 versions prior to 20.3R3
20.4 versions prior to 20.4R3
21.1 versions prior to 21.1R1-S1, 21.1R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS versions and If the HTTP and HTTPS services are disabled then, QID will not be flagged.
Successful exploitation of this vulnerability may allow the attacker to gain control of the device or attack other authenticated user sessions.
Workaround:
To reduce the risk of exploitation of this issue, use access lists or firewall filters to limit access to only trusted administrative networks, hosts and users. Alternatively, J-Web can be disabled.
- JSA69517 -
kb.juniper.net/JSA69517
CVEs related to QID 43929
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA69517 |
|