CVE-2024-21591
published 2024-01-12CVE-2024-21591: An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to…
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.67%
96.8th percentile
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device.
This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory.
This issue affects Juniper Networks Junos OS SRX Series and EX Series:
* Junos OS versions earlier than 20.4R3-S9;
* Junos OS 21.2 versions earlier than 21.2R3-S7;
* Junos OS 21.3 versions earlier than 21.3R3-S5;
* Junos OS 21.4 versions earlier than 21.4R3-S5;
* Junos OS 22.1 versions earlier than 22.1R3-S4;
* Junos OS 22.2 versions earlier than 22.2R3-S3;
* Junos OS 22.3 versions earlier than 22.3R3-S2;
* Junos OS 22.4 versions earlier than 22.4R2-S2, 22.4R3.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | ex_series | — | — |
| juniper | j-web | — | — |
| juniper | junos | < 20.4 | 20.4 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | < 20.4R3-S9 | 20.4R3-S9 |
| juniper_networks | junos_os | >= 21.2 < 21.2R3-S7 | 21.2R3-S7 |
| juniper_networks | junos_os | >= 21.3 < 21.3R3-S5 | 21.3R3-S5 |
| juniper_networks | junos_os | >= 21.4 < 21.4R3-S5 | 21.4R3-S5 |
| juniper_networks | junos_os | >= 22.1 < 22.1R3-S4 | 22.1R3-S4 |
| juniper_networks | junos_os | >= 22.2 < 22.2R3-S3 | 22.2R3-S3 |
| juniper_networks | junos_os | >= 22.3 < 22.3R3-S2 | 22.3R3-S2 |
| juniper_networks | junos_os | >= 22.4 < 22.4R2-S2, 22.4R3 | 22.4R2-S2, 22.4R3 |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack surface is the J-Web interface exposed on Juniper SRX Series firewalls and EX Series switches; disabling or restricting J-Web access removes the attack vector for unauthenticated exploitation. ↗
- →Over 8,200 Juniper devices have J-Web interfaces exposed online (Shadowserver data); over 9,000 tracked by Shodan — prioritize detection/blocking of internet-facing J-Web endpoints. ↗
- →The vulnerability is an out-of-bounds write caused by use of an insecure function allowing arbitrary memory overwrite, exploitable by unauthenticated network-based attackers for RCE with root privileges or DoS on J-Web. ↗
- →Restrict J-Web access to only trusted network hosts as a temporary mitigation until patches are deployed to reduce exposure. ↗
- ·No active in-the-wild exploitation was observed at time of disclosure; however, past Juniper J-Web vulnerabilities (CVE-2023-36844/36845/36846/36847) were exploited within one week of patch release and PoC publication, suggesting rapid weaponization is likely. ↗
- ·Affected platforms are Junos OS SRX Series and EX Series only; patched versions are 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2, 22.4R3, 23.2R1-S1, 23.2R2, 23.4R1, and all subsequent releases. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j7xq-gvq8-pr7m: An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attack
ghsa_unreviewed·2024-01-12
CVE-2024-21591 [CRITICAL] CWE-787 GHSA-j7xq-gvq8-pr7m: An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attack
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device.
This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory.
This issue affects Juniper Networks Junos OS SRX Series and EX Series:
* Junos OS versions earlier than 20.4R3-S9;
* Junos OS 21.2 versions earlier than 21.2R3-S7;
* Junos OS 21.3 versions earlier than 21.3R3-S5;
* Junos OS 21.4 versions earlier than 21.4R3-S5;
* Junos OS 22.1 versions earlier than 22.1R3-S4;
* Junos OS 22.2 versions earlier than 22.2R3-S3;
* Junos OS 22.3 versions earlier than 22.3R3-S2;
* Junos OS 22.4 versi
Juniper
CVE-2024-21591:
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attac
vendor_juniper·2024-01-12·CVSS 9.8
CVE-2024-21591 [CRITICAL] CWE-787 CVE-2024-21591:
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attac
CVE-2024-21591:
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device.
This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory.
This issue affects Juniper Networks Junos OS SRX Series and EX Series:
* Junos OS versions earlier than 20.4R3-S9;
* Junos OS 21.2 versions earlier than 21.2R3-S7;
* Junos OS 21.3 versions earlier than 21.3R3-S5;
* Junos OS 21.4 versions earlier than 21.4R3-S5;
* Junos OS 22.1 versions earlier than 22.1R3-S4;
* Junos OS 22.2 versions earlier than 22.2R3-S3;
* Junos OS 22.3 versions earlier than 22.3R3-S2;
* Jun
No detection rules found.
No public exploits indexed.
Checkpoint
29th January – Threat Intelligence Report
blogs_checkpoint·2024-01-29
CVE-2024-23222 29th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th January, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Following the reports on Russia-affiliated APT29 (AKA Cozy Bear, Midnight Blizzard) attack against Microsoft, also Hewlett-Packard Enterprise acknowledged it was attacked by the same threat actor. While Microsoft detected the breach on January 12 and the password-spray attack began in November 2023; HPE’s investigation po
Bleepingcomputer
Juniper warns of critical RCE bug in its firewalls and switches
blogs_bleepingcomputer·2024-01-12·CVSS 9.8
CVE-2024-21591 [CRITICAL] Juniper warns of critical RCE bug in its firewalls and switches
## Juniper warns of critical RCE bug in its firewalls and switches
## Sergiu Gatlan
Juniper Networks has released security updates to fix a critical pre-auth remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches.
Found in the devices' J-Web configuration interfaces and tracked as CVE-2024-21591, this critical security flaw can also be exploited by unauthenticated threat actors to get root privileges or launch denial-of-service (DoS) attacks against unpatched devices.
"This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory," the company explained in a security advisory published Wednesday.
At the moment, Juniper's Security Incident Response Team has no evidence that the vulnerability is being exploit
https://curesec.com/blog/article/CVE-2024-21591_Juniper_Remote_Code_Exec.htmlhttps://supportportal.juniper.net/JSA75729https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:Nhttps://curesec.com/blog/article/CVE-2024-21591_Juniper_Remote_Code_Exec.htmlhttps://supportportal.juniper.net/JSA75729https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
2024-01-12
Published