Rewterz
Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
November 8, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-34979 – NETGEAR routers Vulnerability
November 9, 2021

Rewterz Threat Advisory – CVE-2021-31385 – Juniper Networks Junos OS

Severity

High

Analysis Summary

CVE-2021-31385

Juniper Networks Junos OS could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a path traversal flaw in J-Web. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges as root.

Impact

  • Privilege Escalation

Affected Vendors

  • Juniper

Affected Products

  • Juniper Networks Junos OS 15.1
  • Juniper Networks Junos OS 18.3
  • Juniper Networks Junos OS 18.4
  • Juniper Networks Junos OS 19.1
  • Juniper Networks Junos OS 19.2
  • Juniper Networks Junos OS 12.3
  • Juniper Networks Junos OS 19.3
  • Juniper Networks Junos OS 19.4
  • Juniper Networks Junos OS 20.1
  • Juniper Networks Junos OS 20.2
  • Juniper Networks Junos OS 20.3
  • Juniper Networks Junos OS 20.4
  • Juniper Networks Junos OS 21.1

Remediation

Refer to Juniper Advisory for patch, upgrade, or suggested workaround information.

https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11253&cat=SIRT_1&actp=LIST