PT-2021-5074 · Juniper Networks · 128 Technology Session Smart Router

Published

2021-10-13

·

Updated

2022-10-25

·

CVE-2021-31349

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11 Juniper Networks 128 Technology Session Smart Router versions 5.0 up to and including 5.0.1
Description The usage of an internal HTTP header created an authentication bypass issue, allowing an attacker to view internal files, change settings, manipulate services, and execute arbitrary code. This issue enables a remote attacker to exploit the vulnerability.
Recommendations For versions prior to 4.5.11, update to version 4.5.11 or later. For versions 5.0 up to and including 5.0.1, update to a version later than 5.0.1. As a temporary workaround, consider restricting access to internal files and settings until a patch is available. Restrict access to the router's services to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-05854
CVE-2021-31349

Affected Products

128 Technology Session Smart Router