Lucene search

K
cveJuniperCVE-2024-21619
HistoryJan 25, 2024 - 11:15 p.m.

CVE-2024-21619

2024-01-2523:15:09
CWE-306
CWE-209
juniper
web.nvd.nist.gov
22
cve-2024-21619
juniper networks
junos os
srx series
ex series
missing authentication
information leakage
vulnerability
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

8

Confidence

High

EPSS

0.001

Percentile

39.8%

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information.

When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information.

This issue affects Juniper Networks Junos OS on SRX Series and EX Series:

  • All versions earlier than 20.4R3-S9;
  • 21.2 versions earlier than 21.2R3-S7;
  • 21.3 versions earlier than 21.3R3-S5;
  • 21.4 versions earlier than 21.4R3-S6;
  • 22.1 versions earlier than 22.1R3-S5;
  • 22.2 versions earlier than 22.2R3-S3;
  • 22.3 versions earlier than 22.3R3-S2;
  • 22.4 versions earlier than 22.4R3;
  • 23.2 versions earlier than 23.2R1-S2, 23.2R2.

Affected configurations

Nvd
Node
juniperex_redundant_power_systemMatch-
OR
juniperex_rpsMatch-
OR
juniperex2200Match-
OR
juniperex2200-cMatch-
OR
juniperex2200-vcMatch-
OR
juniperex2300Match-
OR
juniperex2300-24mpMatch-
OR
juniperex2300-24pMatch-
OR
juniperex2300-24tMatch-
OR
juniperex2300-48mpMatch-
OR
juniperex2300-48pMatch-
OR
juniperex2300-48tMatch-
OR
juniperex2300-cMatch-
OR
juniperex2300_multigigabitMatch-
OR
juniperex2300mMatch-
OR
juniperex3200Match-
OR
juniperex3300Match-
OR
juniperex3300-vcMatch-
OR
juniperex3400Match-
OR
juniperex4100Match-
OR
juniperex4100-fMatch-
OR
juniperex4100_multigigabitMatch-
OR
juniperex4200Match-
OR
juniperex4200-vcMatch-
OR
juniperex4300Match-
OR
juniperex4300-24pMatch-
OR
juniperex4300-24p-sMatch-
OR
juniperex4300-24tMatch-
OR
juniperex4300-24t-sMatch-
OR
juniperex4300-32fMatch-
OR
juniperex4300-32f-dcMatch-
OR
juniperex4300-32f-sMatch-
OR
juniperex4300-48mpMatch-
OR
juniperex4300-48mp-sMatch-
OR
juniperex4300-48pMatch-
OR
juniperex4300-48p-sMatch-
OR
juniperex4300-48tMatch-
OR
juniperex4300-48t-afiMatch-
OR
juniperex4300-48t-dcMatch-
OR
juniperex4300-48t-dc-afiMatch-
OR
juniperex4300-48t-sMatch-
OR
juniperex4300-48tafiMatch-
OR
juniperex4300-48tdcMatch-
OR
juniperex4300-48tdc-afiMatch-
OR
juniperex4300-mpMatch-
OR
juniperex4300-vcMatch-
OR
juniperex4300_multigigabitMatch-
OR
juniperex4300mMatch-
OR
juniperex4400Match-
OR
juniperex4400-24xMatch-
OR
juniperex4400_multigigabitMatch-
OR
juniperex4500Match-
OR
juniperex4500-vcMatch-
OR
juniperex4550Match-
OR
juniperex4550-vcMatch-
OR
juniperex4550\/vcMatch-
OR
juniperex4600Match-
OR
juniperex4600-vcMatch-
OR
juniperex4650Match-
OR
juniperex6200Match-
OR
juniperex6210Match-
OR
juniperex8200Match-
OR
juniperex8200-vcMatch-
OR
juniperex8208Match-
OR
juniperex8216Match-
OR
juniperex9200Match-
OR
juniperex9204Match-
OR
juniperex9208Match-
OR
juniperex9214Match-
OR
juniperex9250Match-
OR
juniperex9251Match-
OR
juniperex9253Match-
OR
junipersrx100Match-
OR
junipersrx110Match-
OR
junipersrx1400Match-
OR
junipersrx1500Match-
OR
junipersrx1600Match-
OR
junipersrx210Match-
OR
junipersrx220Match-
OR
junipersrx2300Match-
OR
junipersrx240Match-
OR
junipersrx240h2Match-
OR
junipersrx240mMatch-
OR
junipersrx300Match-
OR
junipersrx320Match-
OR
junipersrx340Match-
OR
junipersrx3400Match-
OR
junipersrx345Match-
OR
junipersrx3600Match-
OR
junipersrx380Match-
OR
junipersrx4000Match-
OR
junipersrx4100Match-
OR
junipersrx4200Match-
OR
junipersrx4300Match-
OR
junipersrx4600Match-
OR
junipersrx4700Match-
OR
junipersrx5000Match-
OR
junipersrx5400Match-
OR
junipersrx550Match-
OR
junipersrx550_hmMatch-
OR
junipersrx550mMatch-
OR
junipersrx5600Match-
OR
junipersrx5800Match-
OR
junipersrx650Match-
AND
juniperjunosRange<20.4
OR
juniperjunosMatch20.4-
OR
juniperjunosMatch20.4r1
OR
juniperjunosMatch20.4r1-s1
OR
juniperjunosMatch20.4r2
OR
juniperjunosMatch20.4r2-s1
OR
juniperjunosMatch20.4r2-s2
OR
juniperjunosMatch20.4r3
OR
juniperjunosMatch20.4r3-s1
OR
juniperjunosMatch20.4r3-s2
OR
juniperjunosMatch20.4r3-s3
OR
juniperjunosMatch20.4r3-s4
OR
juniperjunosMatch20.4r3-s5
OR
juniperjunosMatch20.4r3-s6
OR
juniperjunosMatch20.4r3-s7
OR
juniperjunosMatch20.4r3-s8
OR
juniperjunosMatch21.2-
OR
juniperjunosMatch21.2r1
OR
juniperjunosMatch21.2r1-s1
OR
juniperjunosMatch21.2r1-s2
OR
juniperjunosMatch21.2r2
OR
juniperjunosMatch21.2r2-s1
OR
juniperjunosMatch21.2r2-s2
OR
juniperjunosMatch21.2r3
OR
juniperjunosMatch21.2r3-s1
OR
juniperjunosMatch21.2r3-s2
OR
juniperjunosMatch21.2r3-s3
OR
juniperjunosMatch21.2r3-s4
OR
juniperjunosMatch21.2r3-s5
OR
juniperjunosMatch21.2r3-s6
OR
juniperjunosMatch21.3-
OR
juniperjunosMatch21.3r1
OR
juniperjunosMatch21.3r1-s1
OR
juniperjunosMatch21.3r1-s2
OR
juniperjunosMatch21.3r2
OR
juniperjunosMatch21.3r2-s1
OR
juniperjunosMatch21.3r2-s2
OR
juniperjunosMatch21.3r3
OR
juniperjunosMatch21.3r3-s1
OR
juniperjunosMatch21.3r3-s2
OR
juniperjunosMatch21.3r3-s3
OR
juniperjunosMatch21.3r3-s4
OR
juniperjunosMatch21.4-
OR
juniperjunosMatch21.4r1
OR
juniperjunosMatch21.4r1-s1
OR
juniperjunosMatch21.4r1-s2
OR
juniperjunosMatch21.4r2
OR
juniperjunosMatch21.4r2-s1
OR
juniperjunosMatch21.4r2-s2
OR
juniperjunosMatch21.4r3
OR
juniperjunosMatch21.4r3-s1
OR
juniperjunosMatch21.4r3-s2
OR
juniperjunosMatch21.4r3-s3
OR
juniperjunosMatch21.4r3-s4
OR
juniperjunosMatch21.4r3-s5
OR
juniperjunosMatch22.1-
OR
juniperjunosMatch22.1r1
OR
juniperjunosMatch22.1r1-s1
OR
juniperjunosMatch22.1r1-s2
OR
juniperjunosMatch22.1r2
OR
juniperjunosMatch22.1r2-s1
OR
juniperjunosMatch22.1r2-s2
OR
juniperjunosMatch22.1r3
OR
juniperjunosMatch22.1r3-s1
OR
juniperjunosMatch22.1r3-s2
OR
juniperjunosMatch22.1r3-s3
OR
juniperjunosMatch22.1r3-s4
OR
juniperjunosMatch22.2-
OR
juniperjunosMatch22.2r1
OR
juniperjunosMatch22.2r1-s1
OR
juniperjunosMatch22.2r1-s2
OR
juniperjunosMatch22.2r2
OR
juniperjunosMatch22.2r2-s1
OR
juniperjunosMatch22.2r2-s2
OR
juniperjunosMatch22.2r3
OR
juniperjunosMatch22.2r3-s1
OR
juniperjunosMatch22.2r3-s2
OR
juniperjunosMatch22.3-
OR
juniperjunosMatch22.3r1
OR
juniperjunosMatch22.3r1-s1
OR
juniperjunosMatch22.3r1-s2
OR
juniperjunosMatch22.3r2
OR
juniperjunosMatch22.3r2-s1
OR
juniperjunosMatch22.3r2-s2
OR
juniperjunosMatch22.3r3
OR
juniperjunosMatch22.3r3-s1
OR
juniperjunosMatch22.4-
OR
juniperjunosMatch22.4r1
OR
juniperjunosMatch22.4r1-s1
OR
juniperjunosMatch22.4r1-s2
OR
juniperjunosMatch22.4r2
OR
juniperjunosMatch22.4r2-s1
OR
juniperjunosMatch22.4r2-s2
OR
juniperjunosMatch23.2-
OR
juniperjunosMatch23.2r1
OR
juniperjunosMatch23.2r1-s1
VendorProductVersionCPE
juniperex_redundant_power_system-cpe:2.3:h:juniper:ex_redundant_power_system:-:*:*:*:*:*:*:*
juniperex_rps-cpe:2.3:h:juniper:ex_rps:-:*:*:*:*:*:*:*
juniperex2200-cpe:2.3:h:juniper:ex2200:-:*:*:*:*:*:*:*
juniperex2200-c-cpe:2.3:h:juniper:ex2200-c:-:*:*:*:*:*:*:*
juniperex2200-vc-cpe:2.3:h:juniper:ex2200-vc:-:*:*:*:*:*:*:*
juniperex2300-cpe:2.3:h:juniper:ex2300:-:*:*:*:*:*:*:*
juniperex2300-24mp-cpe:2.3:h:juniper:ex2300-24mp:-:*:*:*:*:*:*:*
juniperex2300-24p-cpe:2.3:h:juniper:ex2300-24p:-:*:*:*:*:*:*:*
juniperex2300-24t-cpe:2.3:h:juniper:ex2300-24t:-:*:*:*:*:*:*:*
juniperex2300-48mp-cpe:2.3:h:juniper:ex2300-48mp:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 2001

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "SRX Series",
      "EX Series"
    ],
    "product": "Junos OS",
    "vendor": "Juniper Networks",
    "versions": [
      {
        "lessThan": "20.4R3-S9",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThan": "21.2R3-S7",
        "status": "affected",
        "version": "21.2",
        "versionType": "semver"
      },
      {
        "lessThan": "21.3R3-S5",
        "status": "affected",
        "version": "21.3",
        "versionType": "semver"
      },
      {
        "lessThan": "21.4R3-S6",
        "status": "affected",
        "version": "21.4",
        "versionType": "semver"
      },
      {
        "lessThan": "22.1R3-S5",
        "status": "affected",
        "version": "22.1",
        "versionType": "semver"
      },
      {
        "lessThan": "22.2R3-S3",
        "status": "affected",
        "version": "22.2",
        "versionType": "semver"
      },
      {
        "lessThan": "22.3R3-S2",
        "status": "affected",
        "version": "22.3",
        "versionType": "semver"
      },
      {
        "lessThan": "22.4R3",
        "status": "affected",
        "version": "22.4",
        "versionType": "semver"
      },
      {
        "lessThan": "23.2R1-S2, 23.2R2",
        "status": "affected",
        "version": "23.2",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

8

Confidence

High

EPSS

0.001

Percentile

39.8%

Related for CVE-2024-21619