CVE-2024-21619: Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information.
When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information.
This issue affects Juniper Networks Junos OS on SRX Series and EX Series: All versions earlier than 20.4R3-S9; 21.2 versions earlier than 21.2R3-S7; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S6; 22.1 versions earlier than 22.1R3-S5; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S2; 22.4 versions earlier than 22.4R3; 23.2 versions earlier than 23.2R1-S2, 23.2R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 20.4R3-S9 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 21.2R3-S7 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 21.3R3-S5 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 21.4R3-S6 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 22.1R3-S5 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 22.2R3-S3 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 22.3R3-S2 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 22.4R3 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 23.2R1-S2 - Upgrade
Upgrade
Junos OS (J-Web) on SRX/EX seriesto a version that resolves this vulnerability.Fixed in 23.2R2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-21619?
CVE-2024-21619 is rated as a critical vulnerability due to its potential for unauthenticated access to sensitive information.
How do I fix CVE-2024-21619?
To fix CVE-2024-21619, update your Junos OS to the latest patched version provided by Juniper Networks.
Which products are affected by CVE-2024-21619?
CVE-2024-21619 affects Juniper Networks Junos OS on the SRX Series and EX Series devices.
What types of attacks can exploit CVE-2024-21619?
CVE-2024-21619 can be exploited by unauthenticated, network-based attackers to gain access to sensitive information.
Is CVE-2024-21619 associated with any specific versions of Junos OS?
Yes, CVE-2024-21619 affects specific versions of Junos OS up to 20.4, including various subsequent releases.