Juniper Networks has disclosed separate vulnerabilities it was previously accused of concealing, and apologized to customers for the error in communication. The update, which happened late last week, comes hot on the heels of reporting from El Reg that highlighted how multiple security vendors were accused of bending the rules when it came to assigning CVEs for vulnerabilities in their products. The four vulnerabilities reported to Juniper Networks by watchTowr researcher Aliz Hammond, which were later found to be missing individual CVEs, have now each been disclosed separately, per an out-of-cycle security advisory. Despite submitting four vulnerability reports in total, Juniper credited watchTowr with the discovery of just two. The two other CVEs were apparently fixed in the original batch of updates – watchTowr is thought to have just rediscovered them – but they each now have their own distinct CVE. The advisory details three separate missing authentication vulnerabilities, each carrying a 5.3 severity score, and an 8.8-severity cross-site scripting (XSS) flaw that could lead to code execution with admin privileges if exploited. The newly disclosed issues affect J-Web in Junos OS SRX Series and EX Series, and are tracked as: CVE-2024-21619 CVE-2023-36846 CVE-2024-21620 CVE-2023-36851 "Multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS on SRX Series and EX Series have been resolved through the application of specific fixes to address each vulnerab...
Reg story prompts fresh security bulletin, review of Juniper Networks' CVE process
The Register
·Connor Jones
·Published Jan 30, 2024
·Updated
Affected Software
3 affected components
Juniper Networks Junos OS
Juniper Networks SRX Series
Juniper Networks EX Series
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the disclosure of vulnerabilities by Juniper Networks and their apology for past miscommunication regarding these issues.
2
What security implications are discussed?
The implications include potential risks to users of Juniper's products due to previously uncommunicated vulnerabilities.
3
What products or software are affected?
The affected products include Junos OS, SRX Series, and EX Series from Juniper Networks.
4
What action did Juniper Networks take in response to the vulnerabilities?
Juniper Networks issued a fresh security bulletin and reviewed its CVE process following the disclosure of the vulnerabilities.
5
Why did Juniper Networks apologize to its customers?
Juniper Networks apologized for the error in communication regarding the vulnerabilities that were previously accused of being concealed.