Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web.
This issue affects:
Juniper Networks Junos OS SRX Series
This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.
The following minimal configuration is necessary:
[system services web-management http]
or
[system services web-management https]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was found during internal product security testing or research.
This issue has been assigned CVE-2021-31384 .
The following software releases have been updated to resolve this specific issue: 20.4R2-S1, 20.4R3, 21.1R1-S1, 21.1R2, 21.2R1, and all subsequent releases.
This issue is being tracked as 1577816 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2021-10-13: Initial Publication.