PT-2021-12976 · Juniper Networks · Junos

Published

2021-04-22

·

Updated

2022-08-05

·

CVE-2021-0268

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Juniper Networks Junos OS versions prior to 18.1R3-S11 Juniper Networks Junos OS versions prior to 18.2R3-S5 Juniper Networks Junos OS versions prior to 18.3R2-S4, 18.3R3-S3 Juniper Networks Junos OS versions prior to 18.4R2-S5, 18.4R3-S3 Juniper Networks Junos OS versions prior to 19.1R2-S2, 19.1R3-S2 Juniper Networks Junos OS versions prior to 19.2R1-S5, 19.2R2 Juniper Networks Junos OS versions prior to 19.3R3 Juniper Networks Junos OS versions prior to 19.4R1-S3, 19.4R2, 19.4R3 Juniper Networks Junos OS versions prior to 20.1R1-S2, 20.1R2
Description: An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration information from the device without authentication. The weakness can be exploited to facilitate cross-site scripting (XSS), cookie manipulation (modifying session cookies, stealing cookies) and more. This weakness can also be exploited by directing a user to a seemingly legitimate link from the affected site. The attacker requires no special access or permissions to the device to carry out such attacks.
Recommendations: For Juniper Networks Junos OS versions prior to 18.1R3-S11, update to version 18.1R3-S11 or later. For Juniper Networks Junos OS versions prior to 18.2R3-S5, update to version 18.2R3-S5 or later. For Juniper Networks Junos OS versions prior to 18.3R2-S4, 18.3R3-S3, update to version 18.3R2-S4, 18.3R3-S3 or later. For Juniper Networks Junos OS versions prior to 18.4R2-S5, 18.4R3-S3, update to version 18.4R2-S5, 18.4R3-S3 or later. For Juniper Networks Junos OS versions prior to 19.1R2-S2, 19.1R3-S2, update to version 19.1R2-S2, 19.1R3-S2 or later. For Juniper Networks Junos OS versions prior to 19.2R1-S5, 19.2R2, update to version 19.2R1-S5, 19.2R2 or later. For Juniper Networks Junos OS versions prior to 19.3R3, update to version 19.3R3 or later. For Juniper Networks Junos OS versions prior to 19.4R1-S3, 19.4R2, 19.4R3, update to version 19.4R1-S3, 19.4R2, 19.4R3 or later. For Juniper Networks Junos OS versions prior to 20.1R1-S2, 20.1R2, update to version 20.1R1-S2, 20.1R2 or later.

Fix

Buffer Overflow

XSS

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-0268

Affected Products

Junos