QID 44168
Date Published: 2024-02-01
QID 44168: Juniper Network Operating System (Junos OS) Cross-Site Scripting (XSS) Vulnerability (JSA76390)
CVE-2024-21620: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series.
These issues affect Juniper Networks Junos OS on EX and SRX Series
Affected Juniper Networks Junos OS versions:
All versions earlier than 20.4R3-S10
21.2 versions earlier than 21.2R3-S8
21.4 versions earlier than 21.4R3-S6
22.1 versions earlier than 22.1R3-S5
22.2 versions earlier than 22.2R3-S3
22.3 versions earlier than 22.3R3-S2
22.4 versions earlier than 22.4R3-S1
23.2 versions earlier than 23.2R2
23.4 versions earlier than 23.4R2
QID detection logic: (Authenticated)
This QID checks for vulnerable Junos OS version.
QID detection logic: (Unauthenticated)
This QID checks SNMP banner for vulnerable version of JunOS.
Successful exploitation may allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator.
Workaround:
Disable J-Web, or limit access to only trusted hosts.
- JSA76390 -
supportportal.juniper.net/JSA76390
CVEs related to QID 44168
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA76390 |
|