9.8

CVE-2020-1631

Warnung

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal. Using this vulnerability, an attacker may be able to inject commands into the httpd.log, read files with 'world' readable permission file or obtain J-Web session tokens. In the case of command injection, as the HTTP service runs as user 'nobody', the impact of this command injection is limited. (CVSS score 5.3, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) In the case of reading files with 'world' readable permission, in Junos OS 19.3R1 and above, the unauthenticated attacker would be able to read the configuration file. (CVSS score 5.9, vector CVSS:3.1/ AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) If J-Web is enabled, the attacker could gain the same level of access of anyone actively logged into J-Web. If an administrator is logged in, the attacker could gain administrator access to J-Web. (CVSS score 8.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) This issue only affects Juniper Networks Junos OS devices with HTTP/HTTPS services enabled. Junos OS devices with HTTP/HTTPS services disabled are not affected. If HTTP/HTTPS services are enabled, the following command will show the httpd processes: user@device> show system processes | match http 5260 - S 0:00.13 /usr/sbin/httpd-gk -N 5797 - I 0:00.10 /usr/sbin/httpd --config /jail/var/etc/httpd.conf To summarize: If HTTP/HTTPS services are disabled, there is no impact from this vulnerability. If HTTP/HTTPS services are enabled and J-Web is not in use, this vulnerability has a CVSS score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). If J-Web is enabled, this vulnerability has a CVSS score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Juniper SIRT has received a single report of this vulnerability being exploited in the wild. Out of an abundance of caution, we are notifying customers so they can take appropriate actions. Indicators of Compromise: The /var/log/httpd.log may have indicators that commands have injected or files being accessed. The device administrator can look for these indicators by searching for the string patterns "=*;*&" or "*%3b*&" in /var/log/httpd.log, using the following command: user@device> show log httpd.log | match "=*;*&|=*%3b*&" If this command returns any output, it might be an indication of malicious attempts or simply scanning activities. Rotated logs should also be reviewed, using the following command: user@device> show log httpd.log.0.gz | match "=*;*&|=*%3b*&" user@device> show log httpd.log.1.gz | match "=*;*&|=*%3b*&" Note that a skilled attacker would likely remove these entries from the local log file, thus effectively eliminating any reliable signature that the device had been attacked. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S16; 12.3X48 versions prior to 12.3X48-D101, 12.3X48-D105; 14.1X53 versions prior to 14.1X53-D54; 15.1 versions prior to 15.1R7-S7; 15.1X49 versions prior to 15.1X49-D211, 15.1X49-D220; 16.1 versions prior to 16.1R7-S8; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R1-S7, 18.4R3-S2 ; 18.4 version 18.4R2 and later versions; 19.1 versions prior to 19.1R1-S5, 19.1R3-S1; 19.1 version 19.1R2 and later versions; 19.2 versions prior to 19.2R2; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S2, 19.4R2; 20.1 versions prior to 20.1R1-S1, 20.1R2.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperJunos Version12.3 Update-
JuniperJunos Version12.3 Updater1
JuniperJunos Version12.3 Updater10
JuniperJunos Version12.3 Updater10-s1
JuniperJunos Version12.3 Updater10-s2
JuniperJunos Version12.3 Updater11
JuniperJunos Version12.3 Updater12
JuniperJunos Version12.3 Updater12-s1
JuniperJunos Version12.3 Updater12-s11
JuniperJunos Version12.3 Updater12-s12
JuniperJunos Version12.3 Updater12-s13
JuniperJunos Version12.3 Updater12-s14
JuniperJunos Version12.3 Updater12-s15
JuniperJunos Version12.3 Updater12-s3
JuniperJunos Version12.3 Updater12-s4
JuniperJunos Version12.3 Updater12-s6
JuniperJunos Version12.3 Updater12-s8
JuniperJunos Version12.3x48 Update-
JuniperJunos Version12.3x48 Updated10
JuniperJunos Version12.3x48 Updated100
JuniperJunos Version12.3x48 Updated15
JuniperJunos Version12.3x48 Updated20
JuniperJunos Version12.3x48 Updated25
JuniperJunos Version12.3x48 Updated30
JuniperJunos Version12.3x48 Updated35
JuniperJunos Version12.3x48 Updated40
JuniperJunos Version12.3x48 Updated45
JuniperJunos Version12.3x48 Updated50
JuniperJunos Version12.3x48 Updated51
JuniperJunos Version12.3x48 Updated55
JuniperJunos Version12.3x48 Updated60
JuniperJunos Version12.3x48 Updated65
JuniperJunos Version12.3x48 Updated70
JuniperJunos Version12.3x48 Updated75
JuniperJunos Version12.3x48 Updated80
JuniperJunos Version12.3x48 Updated85
JuniperJunos Version12.3x48 Updated90
JuniperJunos Version12.3x48 Updated95
JuniperJunos Version14.1x53 Update-
JuniperJunos Version14.1x53 Updated10
JuniperJunos Version14.1x53 Updated15
JuniperJunos Version14.1x53 Updated16
JuniperJunos Version14.1x53 Updated25
JuniperJunos Version14.1x53 Updated26
JuniperJunos Version14.1x53 Updated27
JuniperJunos Version14.1x53 Updated30
JuniperJunos Version14.1x53 Updated35
JuniperJunos Version14.1x53 Updated40
JuniperJunos Version14.1x53 Updated42
JuniperJunos Version14.1x53 Updated43
JuniperJunos Version14.1x53 Updated44
JuniperJunos Version14.1x53 Updated45
JuniperJunos Version14.1x53 Updated46
JuniperJunos Version14.1x53 Updated47
JuniperJunos Version14.1x53 Updated48
JuniperJunos Version14.1x53 Updated49
JuniperJunos Version14.1x53 Updated50
JuniperJunos Version14.1x53 Updated51
JuniperJunos Version14.1x53 Updated52
JuniperJunos Version14.1x53 Updated53
JuniperJunos Version15.1 Update-
JuniperJunos Version15.1 Updatea1
JuniperJunos Version15.1 Updatef
JuniperJunos Version15.1 Updatef1
JuniperJunos Version15.1 Updatef2
JuniperJunos Version15.1 Updatef2-s1
JuniperJunos Version15.1 Updatef2-s2
JuniperJunos Version15.1 Updatef2-s3
JuniperJunos Version15.1 Updatef2-s4
JuniperJunos Version15.1 Updatef3
JuniperJunos Version15.1 Updatef4
JuniperJunos Version15.1 Updatef5
JuniperJunos Version15.1 Updatef5-s7
JuniperJunos Version15.1 Updatef6
JuniperJunos Version15.1 Updatef6-s1
JuniperJunos Version15.1 Updatef6-s12
JuniperJunos Version15.1 Updatef6-s2
JuniperJunos Version15.1 Updatef6-s3
JuniperJunos Version15.1 Updatef6-s4
JuniperJunos Version15.1 Updatef6-s7
JuniperJunos Version15.1 Updatef7
JuniperJunos Version15.1 Updater1
JuniperJunos Version15.1 Updater2
JuniperJunos Version15.1 Updater3
JuniperJunos Version15.1 Updater4
JuniperJunos Version15.1 Updater4-s7
JuniperJunos Version15.1 Updater4-s8
JuniperJunos Version15.1 Updater4-s9
JuniperJunos Version15.1 Updater5
JuniperJunos Version15.1 Updater5-s1
JuniperJunos Version15.1 Updater5-s5
JuniperJunos Version15.1 Updater5-s6
JuniperJunos Version15.1 Updater6
JuniperJunos Version15.1 Updater6-s1
JuniperJunos Version15.1 Updater6-s2
JuniperJunos Version15.1 Updater6-s6
JuniperJunos Version15.1 Updater7
JuniperJunos Version15.1 Updater7-s1
JuniperJunos Version15.1 Updater7-s2
JuniperJunos Version15.1 Updater7-s3
JuniperJunos Version15.1 Updater7-s4
JuniperJunos Version15.1 Updater7-s5
JuniperJunos Version15.1x49 Update-
JuniperJunos Version15.1x49 Updated10
JuniperJunos Version15.1x49 Updated100
JuniperJunos Version15.1x49 Updated110
JuniperJunos Version15.1x49 Updated120
JuniperJunos Version15.1x49 Updated130
JuniperJunos Version15.1x49 Updated140
JuniperJunos Version15.1x49 Updated15
JuniperJunos Version15.1x49 Updated150
JuniperJunos Version15.1x49 Updated160
JuniperJunos Version15.1x49 Updated170
JuniperJunos Version15.1x49 Updated180
JuniperJunos Version15.1x49 Updated190
JuniperJunos Version15.1x49 Updated20
JuniperJunos Version15.1x49 Updated200
JuniperJunos Version15.1x49 Updated210
JuniperJunos Version15.1x49 Updated25
JuniperJunos Version15.1x49 Updated30
JuniperJunos Version15.1x49 Updated35
JuniperJunos Version15.1x49 Updated40
JuniperJunos Version15.1x49 Updated45
JuniperJunos Version15.1x49 Updated50
JuniperJunos Version15.1x49 Updated55
JuniperJunos Version15.1x49 Updated60
JuniperJunos Version15.1x49 Updated65
JuniperJunos Version15.1x49 Updated70
JuniperJunos Version15.1x49 Updated75
JuniperJunos Version15.1x49 Updated80
JuniperJunos Version15.1x49 Updated90
JuniperJunos Version16.1 Update-
JuniperJunos Version16.1 Updater1
JuniperJunos Version16.1 Updater2
JuniperJunos Version16.1 Updater3
JuniperJunos Version16.1 Updater3-s10
JuniperJunos Version16.1 Updater3-s11
JuniperJunos Version16.1 Updater4
JuniperJunos Version16.1 Updater4-s12
JuniperJunos Version16.1 Updater4-s2
JuniperJunos Version16.1 Updater4-s3
JuniperJunos Version16.1 Updater4-s4
JuniperJunos Version16.1 Updater4-s6
JuniperJunos Version16.1 Updater5
JuniperJunos Version16.1 Updater5-s4
JuniperJunos Version16.1 Updater6-s1
JuniperJunos Version16.1 Updater6-s6
JuniperJunos Version16.1 Updater7
JuniperJunos Version16.1 Updater7-s2
JuniperJunos Version16.1 Updater7-s3
JuniperJunos Version16.1 Updater7-s4
JuniperJunos Version16.1 Updater7-s5
JuniperJunos Version16.1 Updater7-s6
JuniperJunos Version16.1 Updater7-s7
JuniperJunos Version17.2 Update-
JuniperJunos Version17.2 Updater1
JuniperJunos Version17.2 Updater1-s1
JuniperJunos Version17.2 Updater1-s2
JuniperJunos Version17.2 Updater1-s3
JuniperJunos Version17.2 Updater1-s4
JuniperJunos Version17.2 Updater1-s5
JuniperJunos Version17.2 Updater1-s7
JuniperJunos Version17.2 Updater1-s8
JuniperJunos Version17.2 Updater2
JuniperJunos Version17.2 Updater2-s11
JuniperJunos Version17.2 Updater2-s6
JuniperJunos Version17.2 Updater2-s7
JuniperJunos Version17.2 Updater3-s1
JuniperJunos Version17.2 Updater3-s2
JuniperJunos Version17.2 Updater3-s3
JuniperJunos Version17.3 Update-
JuniperJunos Version17.3 Updater1-s1
JuniperJunos Version17.3 Updater2
JuniperJunos Version17.3 Updater2-s1
JuniperJunos Version17.3 Updater2-s2
JuniperJunos Version17.3 Updater2-s3
JuniperJunos Version17.3 Updater2-s4
JuniperJunos Version17.3 Updater3 Edition-
JuniperJunos Version17.3 Updater3-s1
JuniperJunos Version17.3 Updater3-s2
JuniperJunos Version17.3 Updater3-s3
JuniperJunos Version17.3 Updater3-s4
JuniperJunos Version17.3 Updater3-s7
JuniperJunos Version17.4 Update-
JuniperJunos Version17.4 Updater1
JuniperJunos Version17.4 Updater1-s1
JuniperJunos Version17.4 Updater1-s2
JuniperJunos Version17.4 Updater1-s4
JuniperJunos Version17.4 Updater1-s5
JuniperJunos Version17.4 Updater1-s6
JuniperJunos Version17.4 Updater1-s7
JuniperJunos Version17.4 Updater2
JuniperJunos Version17.4 Updater2-s1
JuniperJunos Version17.4 Updater2-s10
JuniperJunos Version17.4 Updater2-s2
JuniperJunos Version17.4 Updater2-s3
JuniperJunos Version17.4 Updater2-s4
JuniperJunos Version17.4 Updater2-s5
JuniperJunos Version17.4 Updater2-s6
JuniperJunos Version17.4 Updater2-s7
JuniperJunos Version17.4 Updater2-s8
JuniperJunos Version17.4 Updater2-s9
JuniperJunos Version17.4 Updater3
JuniperJunos Version17.4 Updater3-s1
JuniperJunos Version18.1 Update-
JuniperJunos Version18.1 Updater2
JuniperJunos Version18.1 Updater2-s1
JuniperJunos Version18.1 Updater2-s2
JuniperJunos Version18.1 Updater2-s4
JuniperJunos Version18.1 Updater3
JuniperJunos Version18.1 Updater3-s1
JuniperJunos Version18.1 Updater3-s2
JuniperJunos Version18.1 Updater3-s3
JuniperJunos Version18.1 Updater3-s4
JuniperJunos Version18.1 Updater3-s6
JuniperJunos Version18.1 Updater3-s7
JuniperJunos Version18.1 Updater3-s8
JuniperJunos Version18.1 Updater3-s9
JuniperJunos Version18.2 Update-
JuniperJunos Version18.2 Updater1-s3
JuniperJunos Version18.2 Updater1-s5
JuniperJunos Version18.2 Updater2-s1
JuniperJunos Version18.2 Updater2-s2
JuniperJunos Version18.2 Updater2-s3
JuniperJunos Version18.2 Updater2-s4
JuniperJunos Version18.2 Updater2-s5
JuniperJunos Version18.2 Updater2-s6
JuniperJunos Version18.2 Updater3
JuniperJunos Version18.2 Updater3-s1
JuniperJunos Version18.2 Updater3-s2
JuniperJunos Version18.2 Updater3-s3
JuniperJunos Version18.3 Update-
JuniperJunos Version18.3 Updater1
JuniperJunos Version18.3 Updater1-s1
JuniperJunos Version18.3 Updater1-s2
JuniperJunos Version18.3 Updater1-s3
JuniperJunos Version18.3 Updater1-s5
JuniperJunos Version18.3 Updater1-s6
JuniperJunos Version18.3 Updater2
JuniperJunos Version18.3 Updater2-s1
JuniperJunos Version18.3 Updater2-s2
JuniperJunos Version18.3 Updater2-s3
JuniperJunos Version18.3 Updater3
JuniperJunos Version18.3 Updater3-s1
JuniperJunos Version18.4 Update-
JuniperJunos Version18.4 Updater1
JuniperJunos Version18.4 Updater1-s1
JuniperJunos Version18.4 Updater1-s2
JuniperJunos Version18.4 Updater1-s3
JuniperJunos Version18.4 Updater1-s4
JuniperJunos Version18.4 Updater1-s5
JuniperJunos Version18.4 Updater1-s6
JuniperJunos Version18.4 Updater2
JuniperJunos Version18.4 Updater2-s1
JuniperJunos Version18.4 Updater2-s2
JuniperJunos Version18.4 Updater2-s3
JuniperJunos Version18.4 Updater3
JuniperJunos Version19.1 Update-
JuniperJunos Version19.1 Updater1
JuniperJunos Version19.1 Updater1-s1
JuniperJunos Version19.1 Updater1-s2
JuniperJunos Version19.1 Updater1-s3
JuniperJunos Version19.1 Updater1-s4
JuniperJunos Version19.2 Update-
JuniperJunos Version19.2 Updater1
JuniperJunos Version19.2 Updater1-s1
JuniperJunos Version19.2 Updater1-s2
JuniperJunos Version19.2 Updater1-s3
JuniperJunos Version19.3 Update-
JuniperJunos Version19.3 Updater1
JuniperJunos Version19.3 Updater1-s1
JuniperJunos Version19.3 Updater2
JuniperJunos Version19.3 Updater2-s1
JuniperJunos Version19.3 Updater2-s2
JuniperJunos Version19.4 Updater1
JuniperJunos Version19.4 Updater1-s1
JuniperJunos Version20.1 Updater1

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Juniper Junos OS Path Traversal Vulnerability

Schwachstelle

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.64% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
sirt@juniper.net 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.