HIGH🇵🇱 Wersja polska

CVE-2026-33779

CVSS 8.3v4.0pub. 2026-04-09upd. 2026-04-17

An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to Security Director (SD) cloud, it doesn't perform sufficient verification of the received server certificate. This allows a PITM to intercept the communication between the SRX and SD cloud and access credentials and other sensitive information. This issue affects Junos OS: * all versions before 22.4R3-S9, * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2.

CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:X
  • Juniper Junos

    OS
    Juniper
    22.423.223.424.224.425.2< 22.4
  • Juniper Srx1500

    HW
    Juniper
    all versions
  • Juniper Srx1600

    HW
    Juniper
    all versions
  • Juniper Srx2300

    HW
    Juniper
    all versions
  • Juniper Srx300

    HW
    Juniper
    all versions
  • Juniper Srx320

    HW
    Juniper
    all versions
  • Juniper Srx340

    HW
    Juniper
    all versions
  • Juniper Srx345

    HW
    Juniper
    all versions
  • Juniper Srx380

    HW
    Juniper
    all versions
  • Juniper Srx4100

    HW
    Juniper
    all versions
  • Juniper Srx4120

    HW
    Juniper
    all versions
  • Juniper Srx4200

    HW
    Juniper
    all versions
  • Juniper Srx4300

    HW
    Juniper
    all versions
  • Juniper Srx4600

    HW
    Juniper
    all versions
  • Juniper Srx4700

    HW
    Juniper
    all versions
  • Juniper Srx5400

    HW
    Juniper
    all versions
  • Juniper Srx5600

    HW
    Juniper
    all versions
  • Juniper Srx5800

    HW
    Juniper
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same product

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2024-21591CRITICAL9.8PL ✓same product

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0248CRITICAL10.0PL ✓same product

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0254CRITICAL9.8PL ✓same product

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message