PT-2021-5074 · Juniper Networks · 128 Technology Session Smart Router

CVE-2021-31349

·

Published

2021-10-13

·

Updated

2022-10-25

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11 Juniper Networks 128 Technology Session Smart Router versions 5.0 up to and including 5.0.1
Description The usage of an internal HTTP header created an authentication bypass issue, allowing an attacker to view internal files, change settings, manipulate services, and execute arbitrary code. This issue enables a remote attacker to exploit the vulnerability.
Recommendations For versions prior to 4.5.11, update to version 4.5.11 or later. For versions 5.0 up to and including 5.0.1, update to a version later than 5.0.1. As a temporary workaround, consider restricting access to internal files and settings until a patch is available. Restrict access to the router's services to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05854
CVE-2021-31349

Affected Products

128 Technology Session Smart Router