Juniper warns of critical RCE bug in its firewalls and switches
ID: e7f45fb0-da80-5313-beed-3d8a51527fc2
STIX ID: report--e7f45fb0-da80-5313-beed-3d8a51527fc2
Feed Name: Bleeping Computer
Juniper disclosed a critical pre-auth remote code execution vulnerability (CVE-2024-21591) in the J‑Web configuration interface of SRX Series firewalls and EX Series switches that can yield root privileges or enable DoS; patches for multiple Junos OS releases have been issued and administrators are urged to apply updates or disable/restrict J‑Web access. Shadowserver and Shodan report thousands of Juniper devices with exposed J‑Web interfaces, increasing the attack surface, and while Juniper reports no active exploitation of this CVE, prior exploited Juniper RCE chains and CISA warnings underscore the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
