A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface. Tampering with this metadata can result in managed SRX Series devices permitting network traffic that should otherwise be blocked by policy, effectively bypassing intended security controls. This issue affects Junos Space Security Director * all versions prior to 24.1R3 Patch V4 This issue does not affect managed cSRX Series devices.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:GreenJuniper Space Security Director
APPJuniper24.1< 24.1Juniper Srx1500
HWJuniperall versionsJuniper Srx1600
HWJuniperall versionsJuniper Srx2300
HWJuniperall versionsJuniper Srx300
HWJuniperall versionsJuniper Srx320
HWJuniperall versionsJuniper Srx340
HWJuniperall versionsJuniper Srx345
HWJuniperall versionsJuniper Srx380
HWJuniperall versionsJuniper Srx4100
HWJuniperall versionsJuniper Srx4120
HWJuniperall versionsJuniper Srx4200
HWJuniperall versionsJuniper Srx4300
HWJuniperall versionsJuniper Srx4600
HWJuniperall versionsJuniper Srx4700
HWJuniperall versionsJuniper Srx5400
HWJuniperall versionsJuniper Srx5600
HWJuniperall versionsJuniper Srx5800
HWJuniperall versionsJuniper Vsrx
APPJuniperall versions
Related vulnerabilities
RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)
Stored XSS w Juniper Space Security Director — wstrzyknięcie złośliwych skryptów
Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message
Zakodowane na stałe dane uwierzytelniające w funkcji UserFW urządzeń Juniper SRX
Race condition w PFE Juniper SRX Series — DoS przez akumulację sesji