Juniper Networks has released security updates to fix a critical pre-auth remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches. Found in the devices' J-Web configuration interfaces and tracked as CVE-2024-21591, this critical security flaw can also be exploited by unauthenticated threat actors to get root privileges or launch denial-of-service (DoS) attacks against unpatched devices. "This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory," the company explained in a security advisory published Wednesday. Juniper added that its Security Incident Response Team has no evidence that the vulnerability is being exploited in the wild. The complete list of vulnerable Junos OS versions affected by the SRX Series and EX Series J-Web bug includes: The bug has been addressed in Junos OS 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2, 22.4R3, 23.2R1-S1, 23.2R2, 23.4R1, and all subsequent releases. Admins are advised to immediately apply the security updates or upgrade JunOS to the latest release or, at least, disable the J-Web interface to remove the attack vector. Another temporary workaround is to restrict J-Web access to only trusted network hosts until patches are deployed. According to data from nonprofit internet security organization Shadowserver, more than 8,200 Juniper devices have their J-Web interfaces exposed online, most from South Korea (Shodan al...
Juniper warns of critical RCE bug in its firewalls and switches
BleepingComputer
·Sergiu Gatlan
·Published Jan 12, 2024
·Updated
Affected Software
2 affected components
Juniper Networks SRX Series firewall
Juniper Networks EX Series switch
Frequently Asked Questions
1
What is the critical issue reported in the article?
The article reports a critical pre-auth remote code execution vulnerability in Juniper Networks' SRX Series firewalls and EX Series switches.
2
What are the specific products affected by this security vulnerability?
The affected products are the Juniper Networks SRX Series firewalls and EX Series switches.
3
How does this vulnerability impact users?
This vulnerability allows attackers to execute remote code without authentication, posing a significant security risk.
4
What action has Juniper Networks taken in response to the vulnerability?
Juniper Networks has released security updates to address the identified vulnerability.
5
What is the tracking identifier for the vulnerability mentioned in the article?
The vulnerability is tracked as CVE-2023-XXXXX.