Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws
ID: b861da0d-58f9-56ca-a9b9-5233dd326dc5
STIX ID: report--b861da0d-58f9-56ca-a9b9-5233dd326dc5
Feed Name: The Hacker News
Juniper Networks issued out-of-cycle patches for two J-Web vulnerabilities (CVE-2024-21619 and CVE-2024-21620) affecting SRX and EX Series Junos OS: CVE-2024-21619 (CVSS 5.3) can expose sensitive configuration due to missing authentication, and CVE-2024-21620 (CVSS 8.8) is an XSS flaw that can allow arbitrary command execution via crafted requests; Juniper lists fixed versions, recommends disabling J-Web or restricting access until patched, and notes related prior vulnerabilities (some added to CISA's KEV) and a recently fixed critical RCE (CVE-2024-21591).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
