First published: Mon Apr 17 2023(Updated: )
An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Networks Junos OS: All versions prior to 19.1R3-S10; 19.2 versions prior to 19.2R3-S7; 19.3 versions prior to 19.3R3-S8; 19.4 versions prior to 19.4R3-S11; 20.1 version 20.1R1 and later versions; 20.2 versions prior to 20.2R3-S7; 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3-S6; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S1; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | <19.4 | |
Juniper Junos | =19.4 | |
Juniper Junos | =19.4-r1 | |
Juniper Junos | =19.4-r1-s1 | |
Juniper Junos | =19.4-r1-s2 | |
Juniper Junos | =19.4-r1-s3 | |
Juniper Junos | =19.4-r1-s4 | |
Juniper Junos | =19.4-r2 | |
Juniper Junos | =19.4-r2-s1 | |
Juniper Junos | =19.4-r2-s2 | |
Juniper Junos | =19.4-r2-s3 | |
Juniper Junos | =19.4-r2-s4 | |
Juniper Junos | =19.4-r2-s5 | |
Juniper Junos | =19.4-r2-s6 | |
Juniper Junos | =19.4-r2-s7 | |
Juniper Junos | =19.4-r3 | |
Juniper Junos | =19.4-r3-s1 | |
Juniper Junos | =19.4-r3-s10 | |
Juniper Junos | =19.4-r3-s2 | |
Juniper Junos | =19.4-r3-s3 | |
Juniper Junos | =19.4-r3-s4 | |
Juniper Junos | =19.4-r3-s5 | |
Juniper Junos | =19.4-r3-s6 | |
Juniper Junos | =19.4-r3-s7 | |
Juniper Junos | =19.4-r3-s8 | |
Juniper Junos | =19.4-r3-s9 | |
Juniper Junos | =20.1 | |
Juniper Junos | =20.1-r1 | |
Juniper Junos | =20.1-r1-s1 | |
Juniper Junos | =20.1-r1-s2 | |
Juniper Junos | =20.1-r1-s3 | |
Juniper Junos | =20.1-r1-s4 | |
Juniper Junos | =20.1-r2 | |
Juniper Junos | =20.1-r2-s1 | |
Juniper Junos | =20.1-r2-s2 | |
Juniper Junos | =20.1-r3 | |
Juniper Junos | =20.1-r3-s1 | |
Juniper Junos | =20.1-r3-s2 | |
Juniper Junos | =20.1-r3-s3 | |
Juniper Junos | =20.1-r3-s4 | |
Juniper Junos | =20.1-r3-s5 | |
Juniper Junos | =20.2 | |
Juniper Junos | =20.2-r1 | |
Juniper Junos | =20.2-r1-s1 | |
Juniper Junos | =20.2-r1-s2 | |
Juniper Junos | =20.2-r1-s3 | |
Juniper Junos | =20.2-r2 | |
Juniper Junos | =20.2-r2-s1 | |
Juniper Junos | =20.2-r2-s2 | |
Juniper Junos | =20.2-r2-s3 | |
Juniper Junos | =20.2-r3 | |
Juniper Junos | =20.2-r3-s1 | |
Juniper Junos | =20.2-r3-s2 | |
Juniper Junos | =20.2-r3-s3 | |
Juniper Junos | =20.2-r3-s4 | |
Juniper Junos | =20.2-r3-s5 | |
Juniper Junos | =20.2-r3-s6 | |
Juniper Junos | =20.3 | |
Juniper Junos | =20.3-r1 | |
Juniper Junos | =20.3-r1-s1 | |
Juniper Junos | =20.3-r1-s2 | |
Juniper Junos | =20.3-r2 | |
Juniper Junos | =20.3-r2-s1 | |
Juniper Junos | =20.3-r3 | |
Juniper Junos | =20.3-r3-s1 | |
Juniper Junos | =20.3-r3-s2 | |
Juniper Junos | =20.3-r3-s3 | |
Juniper Junos | =20.3-r3-s4 | |
Juniper Junos | =20.3-r3-s5 | |
Juniper Junos | =20.3-r3-s6 | |
Juniper Junos | =20.4 | |
Juniper Junos | =20.4-r1 | |
Juniper Junos | =20.4-r1-s1 | |
Juniper Junos | =20.4-r2 | |
Juniper Junos | =20.4-r2-s1 | |
Juniper Junos | =20.4-r2-s2 | |
Juniper Junos | =20.4-r3 | |
Juniper Junos | =20.4-r3-s1 | |
Juniper Junos | =20.4-r3-s2 | |
Juniper Junos | =20.4-r3-s3 | |
Juniper Junos | =20.4-r3-s4 | |
Juniper Junos | =20.4-r3-s5 | |
Juniper Junos | =21.1 | |
Juniper Junos | =21.1-r1 | |
Juniper Junos | =21.1-r1-s1 | |
Juniper Junos | =21.1-r2 | |
Juniper Junos | =21.1-r2-s1 | |
Juniper Junos | =21.1-r2-s2 | |
Juniper Junos | =21.1-r3 | |
Juniper Junos | =21.1-r3-s1 | |
Juniper Junos | =21.1-r3-s2 | |
Juniper Junos | =21.1-r3-s3 | |
Juniper Junos | =21.1-r3-s4 | |
Juniper Junos | =21.1-r3-s5 | |
Juniper Junos | =21.2 | |
Juniper Junos | =21.2-r1 | |
Juniper Junos | =21.2-r1-s1 | |
Juniper Junos | =21.2-r1-s2 | |
Juniper Junos | =21.2-r2 | |
Juniper Junos | =21.2-r2-s1 | |
Juniper Junos | =21.2-r2-s2 | |
Juniper Junos | =21.2-r3 | |
Juniper Junos | =21.2-r3-s1 | |
Juniper Junos | =21.2-r3-s2 | |
Juniper Junos | =21.2-r3-s3 | |
Juniper Junos | =21.3 | |
Juniper Junos | =21.3-r1 | |
Juniper Junos | =21.3-r1-s1 | |
Juniper Junos | =21.3-r1-s2 | |
Juniper Junos | =21.3-r2 | |
Juniper Junos | =21.3-r2-s1 | |
Juniper Junos | =21.3-r2-s2 | |
Juniper Junos | =21.3-r3 | |
Juniper Junos | =21.3-r3-s1 | |
Juniper Junos | =21.3-r3-s2 | |
Juniper Junos | =21.4 | |
Juniper Junos | =21.4-r1 | |
Juniper Junos | =21.4-r1-s1 | |
Juniper Junos | =21.4-r1-s2 | |
Juniper Junos | =21.4-r2 | |
Juniper Junos | =21.4-r2-s1 | |
Juniper Junos | =21.4-r2-s2 | |
Juniper Junos | =21.4-r3 | |
Juniper Junos | =21.4-r3-s1 | |
Juniper Junos | =21.4-r3-s2 | |
Juniper Junos | =22.1-r1 | |
Juniper Junos | =22.1-r1-s1 | |
Juniper Junos | =22.1-r1-s2 | |
Juniper Junos | =22.1-r2 | |
Juniper Junos | =22.1-r2-s1 | |
Juniper Junos | =22.1-r2-s2 | |
Juniper Junos | =22.1-r3 | |
Juniper Junos | =22.2-r1 | |
Juniper Junos | =22.2-r1-s1 | |
Juniper Junos | =22.2-r1-s2 | |
Juniper Junos | =22.2-r2 | |
Juniper Junos | =22.3-r1 | |
Juniper Junos | =22.3-r1-s1 |
The following software releases have been updated to resolve this specific issue: Junos OS 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S11, 20.2R3-S7, 20.4R3-S6, 21.1R3-S5, 21.2R3-S4, 21.3R3-S3, 21.4R3-S3, 22.1R3-S1, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28963 has been classified with a severity rating that poses significant risk due to its potential to allow unauthorized file access.
To mitigate CVE-2023-28963, apply the recommended patches and updates provided by Juniper Networks for affected versions of Junos OS.
CVE-2023-28963 impacts all versions of Junos OS prior to 21.4, including multiple sub-versions up to 19.4.
CVE-2023-28963 allows unauthenticated attackers to potentially read arbitrary files from temporary folders on vulnerable Junos OS devices.
Implementing strict firewall rules to limit access to the affected devices can serve as an immediate workaround until a patch is applied for CVE-2023-28963.