CVSS: v3.1: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities.
These issues affect Juniper Networks Junos OS:
These issues affect devices with J-Web enabled.
Important security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered by a third-party upstream provider.
The following software releases have been updated to resolve these specific issues:
Junos OS: 21.4R3-S8, 22.1R3-S6, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2-S2, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
Note regarding CVE-2023-0568: Only 21.4R3-S7 and older versions of Junos OS are affected by this vulnerability.Note regarding CVE-2023-3824. This issue does not affect any version of Junos OS. The CVE is included for informational purposes only. The effective CVSS rating is 0.0.
These issues are being tracked as 1725808 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.
To reduce the risk of exploitation disable J-Web, or limit access to only trusted hosts.
2024-10-09: Initial Publication