An information leak vulnerability in J-Web may allow unauthenticated remote users with network access to the J-Web service to gain administrative privileges or perform certain administrative actions on the device.
This issue was discovered by an external security researcher.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
No other Juniper Networks products or platforms are affected by this issue.
This issue has been assigned CVE-2016-1279 .
The following software releases have been updated to resolve this specific issue: Junos OS 12.1X46-D45, 12.1X46-D46, 12.1X46-D51, 12.1X47-D35, 12.3R12, 12.3X48-D25, 13.3R10, 13.3R9-S1, 14.1R7, 14.1X53-D35, 14.2R6, 15.1A2, 15.1F4, 15.1X49-D30, 15.1R3 and all subsequent releases.
Note: 12.1X46-D50 does not have this fix!
This issue is being tracked as PR 1114274 and is visible on the Customer Support website.
Disable J-Web, or limit access to only trusted hosts.
2016-07-13: Initial publication 2017-03-05: Category restructure.
Juniper SIRT would like to acknowledge and thank Kyle Lovett and Dor Tumarkin for responsibly reporting this vulnerability.