Multiple J-Web vulnerabilities have been resolved in Juniper Networks Junos OS.
These issues affect:
Juniper Networks Junos OS
The following minimal configuration is necessary:
[system services web-management http]
or
[system services web-management https]
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Junos OS: 12.1X46-D86, 12.3R12-S13, 12.3X48-D80, 15.1F6-S13, 15.1R7-S4, 15.1X49-D171, 15.1X49-D180, 15.1X53-D591, 15.1X53-D69, 16.1R7-S5, 16.2R2-S9, 16.2R3, 17.1R2-S12, 17.1R3, 17.2R1-S8, 17.2R2-S7, 17.2R3-S1, 17.3R2-S5, 17.3R3-S5, 17.4R1-S7, 17.4R2-S6, 17.4R3, 18.1R3-S4, 18.2R1-S5, 18.2R2-S3, 18.2R3, 18.3R1-S3, 18.3R2, 18.4R1-S3, 18.4R2, 19.1R1 and all subsequent releases.
These issues are being tracked as 1417434 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
There are no viable workarounds for these issues other than disabling J-Web.
To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to only trusted administrative networks, hosts and users.
2021-07-14: Initial Publication.
The Juniper SIRT wishes to thank Rishabh Kumar Pandey with Wipro for responsibly reporting one of the issues resolved in this update.