HomeSecurityCISA to federal agencies: Immediately update vulnerabilities in Juniper devices

CISA to federal agencies: Immediately update vulnerabilities in Juniper devices

CISA has warned federal agencies to secure Juniper devices on their networks by Friday, as there are four vulnerabilities being used in attacks remote code execution (RCE)

Juniper vulnerabilities

A week ago, Juniper informed customers that vulnerabilities identified in Juniper's J-Web interface (CVE-2023-36844, CVE-2023-36845, CVE-2023-36846 and CVE-2023-36847) have been successfully exploited by hackers.

“ Juniper SIRT is now aware of the successful exploitation of these vulnerabilities. Customers are urged to upgrade their devices immediately ,” the company said

See also: SysAid: Vulnerability exploited in Clop ransomware attacks

The warnings come after threat monitoring service ShadowServer revealed that it had been detecting exploit attempts since August 25, a week after Juniper updates security to fix the vulnerabilities. Around the same time, security researchers at WatchTowr Labs also released a proof-of-concept (PoC) exploit.

According to Shadowserver data, more than 10,000 Juniper devices have their vulnerable J-Web interfaces exposed to the internet. Most of the devices are located in South Korea.

Administrators are urged to immediately secure their devices by upgrading JunOS to the latest version. Also, in case of failure to apply the update, it is recommended to restrict web access to the J-Web interface.

“Given the simplicity of the exploit and the privileged position that JunOS devices hold in a network, we wouldn’t be surprised to see large-scale exploitation,” researchers at WatchTowr Labs said in August.

See also: QNAP patches critical command injection vulnerabilities in QTS OS

Now, CISA has added the four Juniper vulnerabilities to the List of Known Exploitable Vulnerabilities (KEV), stressing that they pose “significant risks to federal business.”

CISA

With their addition to the CISA KEV list, Federal Civilian Executive Branch Agencies (FCEB) must secure devices on their networks by November 17.

CISA strongly encourages all organizations (and non-federal ones), including private companies, to prioritize patching Juniper vulnerabilities as soon as possible.

If federal agencies fail to secure Juniper devices, they will be exposed to significant risks.

See also: Veeam patches serious vulnerabilities in Veeam ONE

First, vulnerabilities in devices may allow attackers to gain access to sensitive information and data stored on them.

Second, the failure to secure Juniper devices could lead to a loss of trust from the public and other partners, as these vulnerabilities could expose companies to security.

Finally, the vulnerabilities allow remote code execution, so devices could be infected with malware.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS