HomeSecurityJuniper: Critical vulnerability in firewalls and switches

Juniper: Critical vulnerability in firewalls and switches

Juniper Networks has released updates security for a critical pre-auth vulnerability that allows remote code execution (RCE) and is found in SRX Series firewalls and EX Series switches.

Juniper firewalls switches vulnerability

Specifically, the vulnerability is located in the J-Web configuration interfaces of the devices and is tracked as CVE-2024-21591. It could also be used by unauthorized attackers to gain root privileges or launch denial-of-service (DoS) attacks against unpatched devices.

At this time, Juniper has not identified any evidence that the vulnerability has been used in attacks.

See also: Microsoft SharePoint: Critical vulnerability used for attacks

The list of vulnerable Junos OS versions affected by the bug in SRX Series and EX Series J-Web includes:

  • Junos OS versions prior to 20.4R3-S9
  • Junos OS 21.2 versions prior to 21.2R3-S7
  • Junos OS 21.3 versions prior to 21.3R3-S5
  • Junos OS 21.4 versions prior to 21.4R3-S5
  • Junos OS 22.1 versions prior to 22.1R3-S4
  • Junos OS 22.2 versions prior to 22.2R3-S3
  • Junos OS 22.3 versions prior to 22.3R3-S2
  • Junos OS 22.4 versions before 22.4R2-S2, 22.4R3

The vulnerability was fixed in the following Junos OS releases: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2, 22.4R3, 23.2R1-S1, 23.2R2, 23.4R1 and all subsequent releases.

Administrators are advised to updates security or upgrade JunOS to the latest version. If for some reason they are unable to upgrade, they should disable the J-Web interface. Another temporary solution is to restrict access J-Web to only trusted network hosts until patches are deployed.

See also: Serious vulnerability in Bosch smart thermostats

According to data from the company Shadowserver, more than 8,200 Juniper devices have their J-Web interfaces exposed to the internet, which is worrying.

Juniper: Critical vulnerability in firewalls and switches
Juniper: Critical vulnerability in firewalls and switches

Protection from vulnerability that allows remote code execution

Protecting a system from a vulnerability that could allow remote code execution requires a number of steps. First, it is essential to keep the system up to date. Software developers often release updates that fix any vulnerabilities that have been discovered.

Second, using a vulnerability management system can help detect and address vulnerabilities before they are exploited. These systems collect information from various sources to identify potential vulnerabilities and provide recommendations for addressing them.

See also: Cisco Unity Connection: Critical vulnerability grants root privileges

Third, implementing the principles of least privilege can significantly reduce risk. This means that systems and users should only have the necessary permissions and access they need to perform their tasks.

Finally, training staff on security issues can be particularly useful. Usersareof the risks and the tactics used by attackers can better protect systems.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS