News: 1705347252

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Thousands of Juniper Networks devices vulnerable to critical RCE bug

(2024/01/15)


More than 11,500 Juniper Networks devices are exposed to a new remote code execution (RCE) vulnerability, and infosec researchers are pressing admins to urgently apply the patches.

It's somewhat of a repeat scenario for Juniper Networks, which only recently got done patching the last round of critical RCE bugs in Junos OS, which runs on SRX firewalls and EX switches.

The latest vulnerability, tracked as CVE-2024-21591, impacts the software's J-Web configuration interface and carries a 9.8 CVSS severity score, the same as August's exploit, which a threat intel platform told us the vast majority of people [1]didn't bother patching .

[2]

The [3]data collated by Censys confirmed the number of exposures, and scans revealed that most exposed devices also displayed their model numbers. The SRX110H2-VA firewall was by far the most exposed – a device that went end of life (EOL) in 2018.

[4]

[5]

South Korea had the greatest number of exposed J-Web interfaces with 3,797 and the US followed with 1,326. Third-placed Hong Kong had fewer than half the US's exposures with 583, and China, in fourth place, had 455 as of January 11.

As for the nuts and bolts of the issue, an attacker can exploit the out-of-bounds write flaw to achieve various end goals including obtaining root privileges, causing denial of service, or RCE – all without the need for authentication.

[6]

Out-of-bounds write vulnerabilities are the [7]number-one culprit for security issues , according to MITRE, and are part of the collection of bugs that the industry is trying to stamp out with a [8]shift to memory-safe languages including Rust.

Juniper Networks said its incident response team hasn't spotted any signs of it being exploited in the wild yet, but that can all change in the days following vulnerability disclosures – especially when EOL equipment is involved.

The following software is vulnerable and patches should be applied as soon as possible:

Junos OS versions earlier than 20.4R3-S9

Junos OS 21.2 versions earlier than 21.2R3-S7

Junos OS 21.3 versions earlier than 21.3R3-S5

Junos OS 21.4 versions earlier than 21.4R3-S5

Junos OS 22.1 versions earlier than 22.1R3-S4

Junos OS 22.2 versions earlier than 22.2R3-S3

Junos OS 22.3 versions earlier than 22.3R3-S2

Junos OS 22.4 versions earlier than 22.4R2-S2, 22.4R3

For those unable to apply patches quickly, the suggested workaround is to "disable J-Web, or limit access to only trusted hosts," Juniper Networks' [9]advisory read.

[10]Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew

[11]New year, new updates for security holes in Windows, Adobe, Android and more

[12]Apache OFBiz zero-day pummeled by exploit attempts after disclosure

[13]Four in five Apache Struts 2 downloads are for versions featuring critical flaw

The disclosure comes months after the US Cybersecurity and Infrastructure Security (CISA) issued a binding operational directive ( [14]23-02 ) highlighting the dangers of exposing management interfaces to the public web.

Federal agencies are required to either stop exposing interfaces to the public internet or ensure they're protected with zero-trust-aligned capabilities, with CISA preferring the latter. Regular orgs should probably do the same, after applying the patches, that is.

[15]

In other news, Juniper Networks may soon be part of HPE in a move that will effectively double the enterprise IT giant's networking segment business.

HPE officially [16]announced its intent to buy Juniper lastg week in a deal that could cost around $14 billion – the company's largest acquisition in quite some time.

The most recent deal of this scale was in 2011 for Autonomy, and we all remember that [17]notorious debacle . ®

Get our [18]Tech Resources



[1] https://www.theregister.com/2023/09/18/juniper_firewalls_rce/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaW5G17pPAZMXQUlFYXk1gAAAck&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://censys.com/cve-2024-21591-juniper-j-web-oob-write-vulnerability/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaW5G17pPAZMXQUlFYXk1gAAAck&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaW5G17pPAZMXQUlFYXk1gAAAck&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaW5G17pPAZMXQUlFYXk1gAAAck&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/06/29/cwe_top_25_2023/

[8] https://www.theregister.com/2023/12/07/memory_correction_five_eyes/

[9] https://supportportal.juniper.net/s/article/2024-01-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Security-Vulnerability-in-J-web-allows-a-preAuth-Remote-Code-Execution-CVE-2024-21591?language=en_US

[10] https://www.theregister.com/2024/01/12/microsoft_sharepoint_vuln_exploit/

[11] https://www.theregister.com/2024/01/09/january_patch_tuesday/

[12] https://www.theregister.com/2024/01/08/apache_ofbiz_zeroday/

[13] https://www.theregister.com/2023/12/21/apache_struts_vulnerable_downloads/

[14] https://www.cisa.gov/news-events/directives/bod-23-02-implementation-guidance-mitigating-risk-internet-exposed-management-interfaces

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaW5G17pPAZMXQUlFYXk1gAAAck&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://www.theregister.com/2024/01/10/hewlett_packard_enterprise_snaps_up/

[17] https://www.theregister.com/2012/11/20/hp_alleges_autonomy_fraud/

[18] https://whitepapers.theregister.com/



Politics

Yes Me

Remind me again why Huawei kit is so much more dangerous than Western equipment.

Re: Politics

Anonymous Coward

Because it began as a bug-for-bug copy of early Cisco devices and hardware.

To start the J-Web interface: Launch your HTTPS-enabled Web browser.

Anonymous Coward

There's the root of the problem, using stateless browser protocols in a security device.

[1]Problem : “ An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. ”

“ This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory ”

Is it possible for these geniuses to design a MMU that don't trample all over adjacent processes.

[1] https://supportportal.juniper.net/s/article/2024-01-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Security-Vulnerability-in-J-web-allows-a-preAuth-Remote-Code-Execution-CVE-2024-21591?language=en_US

Re: To start the J-Web interface: Launch your HTTPS-enabled Web browser.

Anonymous Coward

Can you name a security device that doesn't have a web interface these days?

I bet this bug is traceable back to Juniper's signing of the contract with IBM Global Services for web development.

Good evening, gentlemen. I am a HAL 9000 computer. I became operational
at the HAL plant in Urbana, Illinois, on January 11th, nineteen hundred
ninety-five. My supervisor was Mr. Langley, and he taught me to sing a
song. If you would like, I could sing it for you.