PT-2021-12976 · Juniper Networks · Junos
Published
2021-04-22
·
Updated
2022-08-05
·
CVE-2021-0268
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Juniper Networks Junos OS versions prior to 18.1R3-S11
Juniper Networks Junos OS versions prior to 18.2R3-S5
Juniper Networks Junos OS versions prior to 18.3R2-S4, 18.3R3-S3
Juniper Networks Junos OS versions prior to 18.4R2-S5, 18.4R3-S3
Juniper Networks Junos OS versions prior to 19.1R2-S2, 19.1R3-S2
Juniper Networks Junos OS versions prior to 19.2R1-S5, 19.2R2
Juniper Networks Junos OS versions prior to 19.3R3
Juniper Networks Junos OS versions prior to 19.4R1-S3, 19.4R2, 19.4R3
Juniper Networks Junos OS versions prior to 20.1R1-S2, 20.1R2
Description:
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration information from the device without authentication. The weakness can be exploited to facilitate cross-site scripting (XSS), cookie manipulation (modifying session cookies, stealing cookies) and more. This weakness can also be exploited by directing a user to a seemingly legitimate link from the affected site. The attacker requires no special access or permissions to the device to carry out such attacks.
Recommendations:
For Juniper Networks Junos OS versions prior to 18.1R3-S11, update to version 18.1R3-S11 or later.
For Juniper Networks Junos OS versions prior to 18.2R3-S5, update to version 18.2R3-S5 or later.
For Juniper Networks Junos OS versions prior to 18.3R2-S4, 18.3R3-S3, update to version 18.3R2-S4, 18.3R3-S3 or later.
For Juniper Networks Junos OS versions prior to 18.4R2-S5, 18.4R3-S3, update to version 18.4R2-S5, 18.4R3-S3 or later.
For Juniper Networks Junos OS versions prior to 19.1R2-S2, 19.1R3-S2, update to version 19.1R2-S2, 19.1R3-S2 or later.
For Juniper Networks Junos OS versions prior to 19.2R1-S5, 19.2R2, update to version 19.2R1-S5, 19.2R2 or later.
For Juniper Networks Junos OS versions prior to 19.3R3, update to version 19.3R3 or later.
For Juniper Networks Junos OS versions prior to 19.4R1-S3, 19.4R2, 19.4R3, update to version 19.4R1-S3, 19.4R2, 19.4R3 or later.
For Juniper Networks Junos OS versions prior to 20.1R1-S2, 20.1R2, update to version 20.1R1-S2, 20.1R2 or later.
Fix
Buffer Overflow
XSS
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos