CVSS: v3.1: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Multiple vulnerabilities in the Juniper Networks Policy Enforcer have been resolved by updating the included version of Python from 2.7 to 3.10.These issues affect Juniper Networks Policy Enforcer versions before 24.1R3.
Important security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered by a third-party upstream provider.
The following software releases have been updated to resolve this specific issue: Policy Enforcer 24.1R3 and all subsequent releases.
This issue is being tracked as 1653070 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.
2026-01-14: Initial Publication