CVE-2023-28962: Junos OS: Unauthenticated access vulnerability in J-Web
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Juniper Networks Junos OS: All versions prior to 19.4R3-S11; 20.1 version 20.1R1 and later versions; 20.2 versions prior to 20.2R3-S7; 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3-S6; 21.1 version 21.1R1 and later versions; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S1; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28962?
CVE-2023-28962 is classified as a critical severity vulnerability.
How do I fix CVE-2023-28962?
To remediate CVE-2023-28962, apply the software updates provided by Juniper Networks that address this vulnerability.
What versions of Junos OS are affected by CVE-2023-28962?
CVE-2023-28962 affects multiple versions of Junos OS including all versions prior to 19.4 as well as specific versions within the 19.4 and later branches.
What type of attack is associated with CVE-2023-28962?
CVE-2023-28962 allows unauthenticated network-based attackers to upload arbitrary files to temporary folders on affected devices.
Is there an instance of CVE-2023-28962 in Junos OS?
Yes, CVE-2023-28962 is a real vulnerability that has been documented and affects Juniper Networks Junos OS.