A vulnerability in J-Web may allow remote attackers to bypass CSRF (Cross-Site Request Forgery) Protection in J-Web. This allows performing administrative actions such as creating new administrative accounts as a means to gain complete control over the device. This issue was found during internal product security testing. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. This issue has been assigned CVE-2013-4689.
The following software releases have been updated to resolve this specific issue:
Disable J-Web, or limit access to only trusted hosts.