HIGH🇬🇧 English

CVE-2026-33779

CVSS 8.3v4.0pub. 2026-04-09upd. 2026-04-17

An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to Security Director (SD) cloud, it doesn't perform sufficient verification of the received server certificate. This allows a PITM to intercept the communication between the SRX and SD cloud and access credentials and other sensitive information. This issue affects Junos OS: * all versions before 22.4R3-S9, * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:X
  • Juniper Junos

    OS
    Juniper
    22.423.223.424.224.425.2< 22.4
  • Juniper Srx1500

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx1600

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx2300

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx300

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx320

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx340

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx345

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx380

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4100

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4120

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4200

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4300

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4600

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4700

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx5400

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx5600

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx5800

    HW
    Juniper
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2024-21591CRITICAL9.8PL ✓ten sam produkt

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0248CRITICAL10.0PL ✓ten sam produkt

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0254CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS

CVE-2021-0211CRITICAL10.0PL ✓ten sam produkt

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message