Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.
2021-10-19T19:15:11.373
2024-11-21T06:05:34.467
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | juniper | junos | 20.4 | Yes |
Operating System | juniper | junos | 20.4 | Yes |
Operating System | juniper | junos | 20.4 | Yes |
Operating System | juniper | junos | 21.1 | Yes |
Hardware | juniper | srx1500 | - | No |
Hardware | juniper | srx300 | - | No |
Hardware | juniper | srx4100 | - | No |
Hardware | juniper | srx4200 | - | No |
Hardware | juniper | srx4600 | - | No |
Hardware | juniper | srx5400 | - | No |
Hardware | juniper | srx550 | - | No |
Hardware | juniper | srx5600 | - | No |
Hardware | juniper | srx5800 | - | No |