QID 44167

Date Published: 2024-02-01

QID 44167: Juniper Network Operating System (Junos OS) Information Disclosure Vulnerability (JSA76390)

CVE-2024-21619: A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series.

These issues affect Juniper Networks Junos OS on EX and SRX Series
Affected Juniper Networks Junos OS versions:
All versions earlier than 20.4R3-S9
21.2 versions earlier than 21.2R3-S7
21.3 versions earlier than 21.3R3-S5
21.4 versions earlier than 21.4R3-S6
22.1 versions earlier than 22.1R3-S5
22.2 versions earlier than 22.2R3-S3
22.3 versions earlier than 22.3R3-S2
22.4 versions earlier than 22.4R3
23.2 versions earlier than 23.2R1-S2, 23.2R2
23.4 versions earlier than 23.4R1

QID detection logic: (Authenticated)
This QID checks for vulnerable Junos OS version.

QID detection logic: (Unauthenticated)
This QID checks SNMP banner for vulnerable version of JunOS.

Successful exploitation of this vulnerability may allows an unauthenticated, network-based attacker to access sensitive system information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 2.6 severity.
  • Solution
    Vendor has released patch addressing the vulnerabilities, for more information please refer JSA76390

    Workaround:
    Disable J-Web, or limit access to only trusted hosts.

    Vendor References

    CVEs related to QID 44167

    Software Advisories
    Advisory ID Software Component Link
    JSA76390 URL Logo supportportal.juniper.net/JSA76390