The JUNOS J-Web management application was found to have un-authenticated pages which allowed anyone with access to the device to be able to create privileged accounts on the router or switch. The exploit was discovered through customer penetration testing with no indication of active exploitation.
All JUNOS software releases built on or after 2009-09-22 have fixed this specific issue. This specifically includes 9.4R3, 9.5R2, 9.6R1, 10.0R1, and all subsequent releases. JUNOS versions prior to 9.4 are not vulnerable . This issue is being tracked as PR 453015. While this PR is not viewable by customers, it can be used as a reference when discussing the issue with JTAC.