CVE-2020-1606: Junos OS: Path traversal vulnerability in J-Web
A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read files with 'world' readable permission and delete files with 'world' writeable permission. This issue does not affect system files that can be accessed only by root user. This issue affects Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S13; 12.3X48 versions prior to 12.3X48-D85 on SRX Series; 14.1X53 versions prior to 14.1X53-D51; 15.1F6 versions prior to 15.1F6-S13; 15.1 versions prior to 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D180 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110 Series; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S2; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R3; 18.3 versions prior to 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R2; 19.1 versions prior to 19.1R1-S4, 19.1R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.3R12-S13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.3X48-D85 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.1X53-D51 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1F6-S13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1R7-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1X49-D180 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1X53-D238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1R4-S13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1R7-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.2R2-S10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.1R3-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.2R1-S9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.2R3-S2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.3R2-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.3R3-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4R2-S9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4R3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.1R3-S8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.2R3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3R2-S3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3R3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.4R2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1R1-S4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1R2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2R1
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1606?
CVE-2020-1606 is rated as a medium severity vulnerability due to its potential to allow unauthorized file access and deletion.
How do I fix CVE-2020-1606?
To fix CVE-2020-1606, update your Juniper Junos OS to the latest version available from Juniper Networks that addresses the vulnerability.
What products are affected by CVE-2020-1606?
CVE-2020-1606 affects multiple versions of Juniper Networks Junos OS, including versions 12.3 to 18.4.
Can CVE-2020-1606 be exploited remotely?
CVE-2020-1606 requires authenticated access, so it cannot be exploited remotely without valid credentials.
What kind of attack can CVE-2020-1606 facilitate?
CVE-2020-1606 can facilitate unauthorized file reading and deletion by authenticated users with appropriate permissions.