A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to installAppPackage.php that doesnt require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of
integrity
for a certain
part of the file system, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on EX Series:
prior to
21.3R3-S5;
prior to
21.4R3-S4;
prior to
22.1R3-S3;
prior to
22.2R3-S1;
prior to
22.3R2-S2, 22.3R3;
prior to
22.4R2-S1, 22.4R3.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Junos | Juniper | * | 20.4 (excluding) |
Junos | Juniper | 20.4 (including) | 20.4 (including) |
Junos | Juniper | 20.4-r1 (including) | 20.4-r1 (including) |
Junos | Juniper | 20.4-r1-s1 (including) | 20.4-r1-s1 (including) |
Junos | Juniper | 20.4-r2 (including) | 20.4-r2 (including) |
Junos | Juniper | 20.4-r2-s1 (including) | 20.4-r2-s1 (including) |
Junos | Juniper | 20.4-r2-s2 (including) | 20.4-r2-s2 (including) |
Junos | Juniper | 20.4-r3 (including) | 20.4-r3 (including) |
Junos | Juniper | 20.4-r3-s1 (including) | 20.4-r3-s1 (including) |
Junos | Juniper | 20.4-r3-s2 (including) | 20.4-r3-s2 (including) |
Junos | Juniper | 20.4-r3-s3 (including) | 20.4-r3-s3 (including) |
Junos | Juniper | 20.4-r3-s4 (including) | 20.4-r3-s4 (including) |
Junos | Juniper | 20.4-r3-s5 (including) | 20.4-r3-s5 (including) |
Junos | Juniper | 20.4-r3-s6 (including) | 20.4-r3-s6 (including) |
Junos | Juniper | 20.4-r3-s7 (including) | 20.4-r3-s7 (including) |
Junos | Juniper | 21.1-r1 (including) | 21.1-r1 (including) |
Junos | Juniper | 21.1-r1-s1 (including) | 21.1-r1-s1 (including) |
Junos | Juniper | 21.1-r2 (including) | 21.1-r2 (including) |
Junos | Juniper | 21.1-r2-s1 (including) | 21.1-r2-s1 (including) |
Junos | Juniper | 21.1-r2-s2 (including) | 21.1-r2-s2 (including) |
Junos | Juniper | 21.1-r3 (including) | 21.1-r3 (including) |
Junos | Juniper | 21.1-r3-s1 (including) | 21.1-r3-s1 (including) |
Junos | Juniper | 21.1-r3-s2 (including) | 21.1-r3-s2 (including) |
Junos | Juniper | 21.1-r3-s3 (including) | 21.1-r3-s3 (including) |
Junos | Juniper | 21.1-r3-s4 (including) | 21.1-r3-s4 (including) |
Junos | Juniper | 21.1-r3-s5 (including) | 21.1-r3-s5 (including) |
Junos | Juniper | 21.2 (including) | 21.2 (including) |
Junos | Juniper | 21.2-r1 (including) | 21.2-r1 (including) |
Junos | Juniper | 21.2-r1-s1 (including) | 21.2-r1-s1 (including) |
Junos | Juniper | 21.2-r1-s2 (including) | 21.2-r1-s2 (including) |
Junos | Juniper | 21.2-r2 (including) | 21.2-r2 (including) |
Junos | Juniper | 21.2-r2-s1 (including) | 21.2-r2-s1 (including) |
Junos | Juniper | 21.2-r2-s2 (including) | 21.2-r2-s2 (including) |
Junos | Juniper | 21.2-r3 (including) | 21.2-r3 (including) |
Junos | Juniper | 21.2-r3-s1 (including) | 21.2-r3-s1 (including) |
Junos | Juniper | 21.2-r3-s2 (including) | 21.2-r3-s2 (including) |
Junos | Juniper | 21.2-r3-s3 (including) | 21.2-r3-s3 (including) |
Junos | Juniper | 21.2-r3-s4 (including) | 21.2-r3-s4 (including) |
Junos | Juniper | 21.2-r3-s5 (including) | 21.2-r3-s5 (including) |
Junos | Juniper | 21.3 (including) | 21.3 (including) |
Junos | Juniper | 21.3-r1 (including) | 21.3-r1 (including) |
Junos | Juniper | 21.3-r1-s1 (including) | 21.3-r1-s1 (including) |
Junos | Juniper | 21.3-r1-s2 (including) | 21.3-r1-s2 (including) |
Junos | Juniper | 21.3-r2 (including) | 21.3-r2 (including) |
Junos | Juniper | 21.3-r2-s1 (including) | 21.3-r2-s1 (including) |
Junos | Juniper | 21.3-r2-s2 (including) | 21.3-r2-s2 (including) |
Junos | Juniper | 21.3-r3 (including) | 21.3-r3 (including) |
Junos | Juniper | 21.3-r3-s1 (including) | 21.3-r3-s1 (including) |
Junos | Juniper | 21.3-r3-s2 (including) | 21.3-r3-s2 (including) |
Junos | Juniper | 21.3-r3-s3 (including) | 21.3-r3-s3 (including) |
Junos | Juniper | 21.3-r3-s4 (including) | 21.3-r3-s4 (including) |
Junos | Juniper | 21.4 (including) | 21.4 (including) |
Junos | Juniper | 21.4-r1 (including) | 21.4-r1 (including) |
Junos | Juniper | 21.4-r1-s1 (including) | 21.4-r1-s1 (including) |
Junos | Juniper | 21.4-r1-s2 (including) | 21.4-r1-s2 (including) |
Junos | Juniper | 21.4-r2 (including) | 21.4-r2 (including) |
Junos | Juniper | 21.4-r2-s1 (including) | 21.4-r2-s1 (including) |
Junos | Juniper | 21.4-r2-s2 (including) | 21.4-r2-s2 (including) |
Junos | Juniper | 21.4-r3 (including) | 21.4-r3 (including) |
Junos | Juniper | 21.4-r3-s1 (including) | 21.4-r3-s1 (including) |
Junos | Juniper | 21.4-r3-s2 (including) | 21.4-r3-s2 (including) |
Junos | Juniper | 21.4-r3-s3 (including) | 21.4-r3-s3 (including) |
Junos | Juniper | 21.4-r3-s4 (including) | 21.4-r3-s4 (including) |
Junos | Juniper | 22.1-r1 (including) | 22.1-r1 (including) |
Junos | Juniper | 22.1-r1-s1 (including) | 22.1-r1-s1 (including) |
Junos | Juniper | 22.1-r1-s2 (including) | 22.1-r1-s2 (including) |
Junos | Juniper | 22.1-r2 (including) | 22.1-r2 (including) |
Junos | Juniper | 22.1-r2-s1 (including) | 22.1-r2-s1 (including) |
Junos | Juniper | 22.1-r2-s2 (including) | 22.1-r2-s2 (including) |
Junos | Juniper | 22.1-r3 (including) | 22.1-r3 (including) |
Junos | Juniper | 22.1-r3-s1 (including) | 22.1-r3-s1 (including) |
Junos | Juniper | 22.1-r3-s2 (including) | 22.1-r3-s2 (including) |
Junos | Juniper | 22.2-r1 (including) | 22.2-r1 (including) |
Junos | Juniper | 22.2-r1-s1 (including) | 22.2-r1-s1 (including) |
Junos | Juniper | 22.2-r1-s2 (including) | 22.2-r1-s2 (including) |
Junos | Juniper | 22.2-r2 (including) | 22.2-r2 (including) |
Junos | Juniper | 22.2-r2-s1 (including) | 22.2-r2-s1 (including) |
Junos | Juniper | 22.2-r2-s2 (including) | 22.2-r2-s2 (including) |
Junos | Juniper | 22.2-r3 (including) | 22.2-r3 (including) |
Junos | Juniper | 22.2-r3-s1 (including) | 22.2-r3-s1 (including) |
Junos | Juniper | 22.3-r1 (including) | 22.3-r1 (including) |
Junos | Juniper | 22.3-r1-s1 (including) | 22.3-r1-s1 (including) |
Junos | Juniper | 22.3-r1-s2 (including) | 22.3-r1-s2 (including) |
Junos | Juniper | 22.3-r2 (including) | 22.3-r2 (including) |
Junos | Juniper | 22.3-r2-s1 (including) | 22.3-r2-s1 (including) |
Junos | Juniper | 22.4-r1 (including) | 22.4-r1 (including) |
Junos | Juniper | 22.4-r1-s1 (including) | 22.4-r1-s1 (including) |
Junos | Juniper | 22.4-r1-s2 (including) | 22.4-r1-s2 (including) |
Junos | Juniper | 22.4-r2 (including) | 22.4-r2 (including) |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.