A Missing Authentication for Critical Function...
Moderate severity
Unreviewed
Published
Sep 27, 2023
to the GitHub Advisory Database
•
Updated Feb 3, 2024
Description
Published by the National Vulnerability Database
Sep 27, 2023
Published to the GitHub Advisory Database
Sep 27, 2023
Last updated
Feb 3, 2024
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to
webauth_operation.php
that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of
integrity
for a certain part of the file system, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on SRX Series:
References