A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of
integrity
for a certain
part of the file system, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on EX Series:
prior to
21.3R3-S5;
prior to
21.4R3-S4;
prior to
22.1R3-S3;
prior to
22.2R3-S1;
prior to
22.3R2-S2, 22.3R3;
prior to
22.4R2-S1, 22.4R3.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 53.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| VPI | 79.50 |
VPI formula vpi-v1
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.