Product Affected

These issues affect all versions of Junos OS.
Medium
6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Problem

Multiple Improper Authentication vulnerabilities in the J-Web component of Juniper Networks Junos OS have been resolved through the application of specific fixes to address each vulnerability.


By chaining exploitation of these vulnerabilities, an unauthenticated network-based attacker may be able to read any file belonging to user "nobody", including sensitive session information.


These issues affect Juniper Networks Junos OS:

  • All versions prior to 19.4R3-S11;
  • 20.1 version 20.1R1 and later versions;
  • 20.2 versions prior to 20.2R3-S7;
  • 20.3 version 20.3R1 and later versions;
  • 20.4 versions prior to 20.4R3-S6;
  • 21.1 version 21.1R1 and later versions;
  • 21.2 versions prior to 21.2R3-S4;
  • 21.3 versions prior to 21.3R3-S3;
  • 21.4 versions prior to 21.4R3-S3;
  • 22.1 versions prior to 22.1R3-S1;
  • 22.2 versions prior to 22.2R2-S1, 22.2R3;
  • 22.3 versions prior to 22.3R1-S2, 22.3R2.


These issues were discovered during external security research.

The specific issues reported and resolved are listed below:

CVECVSSSummary
CVE-2023-289625.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device.
CVE-2023-289635.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device.

Solution

The following software releases have been updated to resolve these specific issues: Junos OS 19.4R3-S11, 20.2R3-S7, 20.4R3-S6, 21.2R3-S4, 21.3R3-S3, 21.4R3-S3, 22.1R3-S1, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.


These issues are being tracked as 1698072 and 1698075


Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
 

Workaround

Disable J-Web, or limit access to only trusted hosts.
 

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

  • 2023-04-12: Initial Publication.

Related Information

Acknowledgements

The Juniper SIRT would like to acknowledge and thank Zitong Wang (CataLpa) of Hatlab, DbappSecurity Co. Ltd. for responsibly reporting this vulnerability.