PT-2021-5074 · Juniper Networks · 128 Technology Session Smart Router
Published
2021-10-13
·
Updated
2022-10-25
·
CVE-2021-31349
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11
Juniper Networks 128 Technology Session Smart Router versions 5.0 up to and including 5.0.1
Description
The usage of an internal HTTP header created an authentication bypass issue, allowing an attacker to view internal files, change settings, manipulate services, and execute arbitrary code. This issue enables a remote attacker to exploit the vulnerability.
Recommendations
For versions prior to 4.5.11, update to version 4.5.11 or later.
For versions 5.0 up to and including 5.0.1, update to a version later than 5.0.1.
As a temporary workaround, consider restricting access to internal files and settings until a patch is available.
Restrict access to the router's services to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
128 Technology Session Smart Router