Back to overview

CVE-2024-2973

CRITICAL
10.0
CVSS 3.1
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device. Only routers or conductors that are running in high-availability redundant configurations are affected by this vulnerability. No other Juniper Networks products or platforms are affected by this issue. This issue affects: Session Smart Router:  * All versions before 5.6.15,  * from 6.0 before 6.1.9-lts,  * from 6.2 before 6.2.5-sts. Session Smart Conductor:  * All versions before 5.6.15,  * from 6.0 before 6.1.9-lts,  * from 6.2 before 6.2.5-sts.  WAN Assurance Router:  * 6.0 versions before 6.1.9-lts,  * 6.2 versions before 6.2.5-sts.

Metadata

CVE ID
CVE-2024-2973
State
PUBLISHED
Assigner
juniper
Reserved
2024-03-26 23:06 UTC
Published
2024-06-27 20:17 UTC
Last updated
2024-08-01 19:32 UTC
Primary CWE
CWE-288
CWE-288 Authentication Bypass Using an Alternate Path or Cha…
Vendor / Product
Juniper Networks / Session Smart Router
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (3)
VendorProductPlatformVersions
Juniper Networks Session Smart Conductor 0 < 5.6.15, 6.0 < 6.1.9-lts, 6.2 < 6.2.5-sts
Juniper Networks Session Smart Router 0 < 5.6.15, 6.0 < 6.1.9-lts, 6.2 < 6.2.5-sts
Juniper Networks WAN Assurance Router 6.0 < 6.1.9-lts, 6.2 < 6.2.5-sts
Weakness (CWE)
CWESourceDescription
CWE-288 cna CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSS scores (2)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/V:C/RE:M/U:Red
Back to overview