A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to user.php that doesnt require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of
integrity
for a certainĀ
part of theĀ file system, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on SRX Series:
prior to
21.3R3-S5;
prior to
21.4R3-S5;
prior to
22.1R3-S3;
prior to
22.2R3-S2;
prior to
22.3R2-S2, 22.3R3;
prior to
22.4R2-S1, 22.4R3.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Srx100 | Juniper | - (including) | - (including) |
Srx110 | Juniper | - (including) | - (including) |
Srx1400 | Juniper | - (including) | - (including) |
Srx1500 | Juniper | - (including) | - (including) |
Srx210 | Juniper | - (including) | - (including) |
Srx220 | Juniper | - (including) | - (including) |
Srx240 | Juniper | - (including) | - (including) |
Srx240h2 | Juniper | - (including) | - (including) |
Srx240m | Juniper | - (including) | - (including) |
Srx300 | Juniper | - (including) | - (including) |
Srx320 | Juniper | - (including) | - (including) |
Srx340 | Juniper | - (including) | - (including) |
Srx3400 | Juniper | - (including) | - (including) |
Srx345 | Juniper | - (including) | - (including) |
Srx3600 | Juniper | - (including) | - (including) |
Srx380 | Juniper | - (including) | - (including) |
Srx4000 | Juniper | - (including) | - (including) |
Srx4100 | Juniper | - (including) | - (including) |
Srx4200 | Juniper | - (including) | - (including) |
Srx4600 | Juniper | - (including) | - (including) |
Srx5000 | Juniper | - (including) | - (including) |
Srx5400 | Juniper | - (including) | - (including) |
Srx550 | Juniper | - (including) | - (including) |
Srx550_hm | Juniper | - (including) | - (including) |
Srx550m | Juniper | - (including) | - (including) |
Srx5600 | Juniper | - (including) | - (including) |
Srx5800 | Juniper | - (including) | - (including) |
Srx650 | Juniper | - (including) | - (including) |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.