CVE-2024-21620: Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator.
A specific invocation of the emitdebugnote method in webauthoperation.php will echo back the data it receives.
This issue affects Juniper Networks Junos OS on SRX Series and EX Series: All versions earlier than 20.4R3-S10; 21.2 versions earlier than 21.2R3-S8; 21.4 versions earlier than 21.4R3-S6; 22.1 versions earlier than 22.1R3-S5; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S2; 22.4 versions earlier than 22.4R3-S1; 23.2 versions earlier than 23.2R2; 23.4 versions earlier than 23.4R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20.4R3-S10* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.2R3-S8* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.4R3-S6* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.1R3-S5* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.2R3-S3* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.3R3-S2* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.4R3-S1* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 23.2R2* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 23.4R2* - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.2R1*
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-21620?
CVE-2024-21620 has a high severity rating due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2024-21620?
To remediate CVE-2024-21620, you should update the Junos OS on affected devices to the latest patched version provided by Juniper Networks.
Which versions of Junos OS are affected by CVE-2024-21620?
CVE-2024-21620 affects several versions of Junos OS prior to the fixed releases, including versions up to 22.4.
What products are impacted by CVE-2024-21620?
CVE-2024-21620 impacts Juniper Networks' SRX Series and EX Series devices running affected versions of Junos OS.
Is there a workaround for CVE-2024-21620?
Currently, no known workarounds for CVE-2024-21620 are recommended apart from applying the security updates.