CVE-2024-39563

Severity CVSS v4.0:
MEDIUM
Type:
CWE-77 Command Injection
Publication date:
11/10/2024
Last modified:
23/01/2026

Description

A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web application, gaining complete control of the device.<br /> <br /> A specific script in the Junos Space web application allows attacker-controlled input from a GET request without sufficient input sanitization. A specially crafted request can exploit this vulnerability to execute arbitrary shell commands on the Junos Space Appliance.<br /> <br /> This issue affects Junos Space 24.1R1. Previous versions of Junos Space are unaffected by this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juniper:junos_space:24.1:r1:*:*:*:*:*:*


References to Advisories, Solutions, and Tools