CVE-2024-39565
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/07/2024
Last modified:
22/01/2026
Description
An Improper Neutralization of Data within XPath Expressions (&#39;XPath Injection&#39;) vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device. <br />
<br />
While an administrator is logged into a J-Web session or has previously logged in and subsequently logged out of their J-Web session, the attacker can arbitrarily execute commands on the target device with the other user&#39;s credentials. In the worst case, the attacker will have full control over the device.<br />
This issue affects Junos OS: <br />
<br />
<br />
<br />
* All versions before 21.2R3-S8, <br />
* from 21.4 before 21.4R3-S7,<br />
* from 22.2 before 22.2R3-S4,<br />
* from 22.3 before 22.3R3-S3,<br />
* from 22.4 before 22.4R3-S2,<br />
* from 23.2 before 23.2R2,<br />
* from 23.4 before 23.4R1-S1, 23.4R2.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:juniper:j-web:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 21.2 (excluding) | |
| cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r2-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r2-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r3-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r3-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r3-s3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r3-s4:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://support.juniper.net/support/downloads/?p=283
- https://supportportal.juniper.net/JSA83023
- https://www.first.org/cvss/calculator/v4-0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y/R:I/V:C/RE:L/U:Amber
- https://support.juniper.net/support/downloads/?p=283
- https://supportportal.juniper.net/JSA83023
- https://www.first.org/cvss/calculator/v4-0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y/R:I/V:C/RE:L/U:Amber



