First published: Wed Apr 10 2019(Updated: )
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting techniques. Additionally, administrators who do not enforce a strong password policy can increase the likelihood of success from brute force attacks. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D49; 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D160; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D495, 15.1X53-D591, 15.1X53-D69; 16.1 versions prior to 16.1R3-S10, 16.1R4-S12, 16.1R6-S6, 16.1R7-S3; 16.1X65 versions prior to 16.1X65-D49; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S2; 17.4 versions prior to 17.4R1-S6, 17.4R2-S2; 18.1 versions prior to 18.1R2-S4, 18.1R3-S1; 18.2 versions prior to 18.2R1-S5; 18.2X75 versions prior to 18.2X75-D30; 18.3 versions prior to 18.3R1-S1.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | >=14.1x53<14.1x53-d49 | |
Juniper Junos | >=15.1<15.1f6-s12 | |
Juniper Junos | >=15.1x49<15.1x49-d160 | |
Juniper Junos | >=15.1x53<15.1x53-d236 | |
Juniper Junos | >=16.1<16.1r3-s10 | |
Juniper Junos | >=16.1x65<16.1x65-d49 | |
Juniper Junos | >=16.2<16.2r2-s7 | |
Juniper Junos | >=17.1<17.1r2-s10 | |
Juniper Junos | >=17.2<17.2r1-s8 | |
Juniper Junos | >=17.3<17.3r3-s2 | |
Juniper Junos | >=17.4<17.4r1-s6 | |
Juniper Junos | >=18.1<18.1r2-s4 | |
Juniper Junos | >=18.2<18.2r1-s5 | |
Juniper Junos | >=18.2x75<18.2x75-d30 | |
Juniper Junos | >=18.3<18.3r1-s1 | |
Juniper Junos | =15.1r7-s3 | |
Juniper Junos | =15.1x53-d69 | |
Juniper Junos | =15.1x53-d495 | |
Juniper Junos | =15.1x53-d591 | |
Juniper Junos | =16.1 | |
Juniper Junos | =17.1 | |
Juniper Junos | =17.2r3-s1 | |
Juniper Junos | =17.4 | |
Juniper Junos | =18.1 |
The following software releases have been updated to resolve this specific issue: Junos OS 14.1X53-D49, 15.1F6-S12, 15.1R7-S3, 15.1X49-D160, 15.1X53-D236, 15.1X53-D495, 15.1X53-D591, 15.1X53-D69, 16.1R3-S10, 16.1R4-S12, 16.1R6-S6, 16.1R7-S3, 16.1X65-D49, 16.2R2-S7, 17.1R2-S10, 17.1R3, 17.2R1-S8, 17.2R3-S1, 17.3R3-S2, 17.4R1-S6, 17.4R2-S2, 18.1R2-S4, 18.1R3-S1, 18.2R1-S5, 18.2X75-D30, 18.3R1-S1, 18.4R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0039 has a high severity rating due to the potential for brute force attacks on Junos OS login credentials.
To fix CVE-2019-0039, it is recommended to disable the REST API if not needed, or to enforce strong password policies.
CVE-2019-0039 affects multiple versions of Junos OS, specifically from versions prior to 15.1 up to 18.1.
CVE-2019-0039 allows attackers to perform brute force attacks on the Junos OS login credentials via the enabled REST API.
Mitigations for CVE-2019-0039 include implementing robust account lockout policies and increasing password complexity.