Vulnerability Database

296,213

Total vulnerabilities in the database

CVE-2020-1631

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal. Using this vulnerability, an attacker may be able to inject commands into the httpd.log, read files with 'world' readable permission file or obtain J-Web session tokens. In the case of command injection, as the HTTP service runs as user 'nobody', the impact of this command injection is limited. (CVSS score 5.3, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) In the case of reading files with 'world' readable permission, in Junos OS 19.3R1 and above, the unauthenticated attacker would be able to read the configuration file. (CVSS score 5.9, vector CVSS:3.1/ AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) If J-Web is enabled, the attacker could gain the same level of access of anyone actively logged into J-Web. If an administrator is logged in, the attacker could gain administrator access to J-Web. (CVSS score 8.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) This issue only affects Juniper Networks Junos OS devices with HTTP/HTTPS services enabled. Junos OS devices with HTTP/HTTPS services disabled are not affected. If HTTP/HTTPS services are enabled, the following command will show the httpd processes: user@device> show system processes | match http 5260 - S 0:00.13 /usr/sbin/httpd-gk -N 5797 - I 0:00.10 /usr/sbin/httpd --config /jail/var/etc/httpd.conf To summarize: If HTTP/HTTPS services are disabled, there is no impact from this vulnerability. If HTTP/HTTPS services are enabled and J-Web is not in use, this vulnerability has a CVSS score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). If J-Web is enabled, this vulnerability has a CVSS score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Juniper SIRT has received a single report of this vulnerability being exploited in the wild. Out of an abundance of caution, we are notifying customers so they can take appropriate actions. Indicators of Compromise: The /var/log/httpd.log may have indicators that commands have injected or files being accessed. The device administrator can look for these indicators by searching for the string patterns "=;&" or "%3b&" in /var/log/httpd.log, using the following command: user@device> show log httpd.log | match "=;&|=%3b&" If this command returns any output, it might be an indication of malicious attempts or simply scanning activities. Rotated logs should also be reviewed, using the following command: user@device> show log httpd.log.0.gz | match "=;&|=%3b&" user@device> show log httpd.log.1.gz | match "=;&|=%3b&" Note that a skilled attacker would likely remove these entries from the local log file, thus effectively eliminating any reliable signature that the device had been attacked. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S16; 12.3X48 versions prior to 12.3X48-D101, 12.3X48-D105; 14.1X53 versions prior to 14.1X53-D54; 15.1 versions prior to 15.1R7-S7; 15.1X49 versions prior to 15.1X49-D211, 15.1X49-D220; 16.1 versions prior to 16.1R7-S8; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R1-S7, 18.4R3-S2 ; 18.4 version 18.4R2 and later versions; 19.1 versions prior to 19.1R1-S5, 19.1R3-S1; 19.1 version 19.1R2 and later versions; 19.2 versions prior to 19.2R2; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S2, 19.4R2; 20.1 versions prior to 20.1R1-S1, 20.1R2.

  • Published: May 4, 2020
  • Updated: Apr 13, 2023
  • CVE: CVE-2020-1631
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P
Software From Fixed in
juniper / junos 15.1x49-d50 15.1x49-d50.x
juniper / junos 15.1x49-d30 15.1x49-d30.x
juniper / junos 15.1-r7 15.1-r7.x
juniper / junos 12.3-r11 12.3-r11.x
juniper / junos 15.1x49-d70 15.1x49-d70.x
juniper / junos 15.1-f1 15.1-f1.x
juniper / junos 15.1x49-d80 15.1x49-d80.x
juniper / junos 14.1x53-d45 14.1x53-d45.x
juniper / junos 15.1-f6-s4 15.1-f6-s4.x
juniper / junos 14.1x53-d15 14.1x53-d15.x
juniper / junos 12.3x48-d10 12.3x48-d10.x
juniper / junos 15.1x49-d110 15.1x49-d110.x
juniper / junos 15.1-f2-s3 15.1-f2-s3.x
juniper / junos 15.1-f7 15.1-f7.x
juniper / junos 15.1x49-d60 15.1x49-d60.x
juniper / junos 14.1x53-d35 14.1x53-d35.x
juniper / junos 14.1x53-d10 14.1x53-d10.x
juniper / junos 16.1-r1 16.1-r1.x
juniper / junos 14.1x53-d40 14.1x53-d40.x
juniper / junos 15.1-r3 15.1-r3.x
juniper / junos 14.1x53-d30 14.1x53-d30.x
juniper / junos 12.3x48-d15 12.3x48-d15.x
juniper / junos 14.1x53-d42 14.1x53-d42.x
juniper / junos 15.1-f2-s2 15.1-f2-s2.x
juniper / junos 12.3-r1 12.3-r1.x
juniper / junos 15.1-r6 15.1-r6.x
juniper / junos 15.1-f4 15.1-f4.x
juniper / junos 15.1-r4 15.1-r4.x
juniper / junos 15.1-f2-s4 15.1-f2-s4.x
juniper / junos 12.3x48-d35 12.3x48-d35.x
juniper / junos 14.1x53-d25 14.1x53-d25.x
juniper / junos 12.3x48-d50 12.3x48-d50.x
juniper / junos 15.1-f5-s7 15.1-f5-s7.x
juniper / junos 15.1-f6-s7 15.1-f6-s7.x
juniper / junos 15.1-f6 15.1-f6.x
juniper / junos 15.1x49-d100 15.1x49-d100.x
juniper / junos 12.3-r12 12.3-r12.x
juniper / junos 15.1-f2 15.1-f2.x
juniper / junos 14.1x53-d27 14.1x53-d27.x
juniper / junos 12.3x48-d30 12.3x48-d30.x
juniper / junos 15.1x49-d35 15.1x49-d35.x
juniper / junos 15.1-a1 15.1-a1.x
juniper / junos 17.2-r1 17.2-r1.x
juniper / junos 16.1-r4-s4 16.1-r4-s4.x
juniper / junos 15.1-f3 15.1-f3.x
juniper / junos 15.1-r2 15.1-r2.x
juniper / junos 14.1x53-d16 14.1x53-d16.x
juniper / junos 16.1-r4 16.1-r4.x
juniper / junos 15.1-r4-s7 15.1-r4-s7.x
juniper / junos 15.1x49-d45 15.1x49-d45.x
juniper / junos 12.3-r10 12.3-r10.x
juniper / junos 15.1-r4-s8 15.1-r4-s8.x
juniper / junos 16.1-r4-s3 16.1-r4-s3.x
juniper / junos 15.1x49-d75 15.1x49-d75.x
juniper / junos 15.1x49-d65 15.1x49-d65.x
juniper / junos 15.1-r5-s5 15.1-r5-s5.x
juniper / junos 15.1x49-d90 15.1x49-d90.x
juniper / junos 14.1x53-d43 14.1x53-d43.x
juniper / junos 15.1-r6-s1 15.1-r6-s1.x
juniper / junos 12.3x48-d25 12.3x48-d25.x
juniper / junos 14.1x53-d44 14.1x53-d44.x
juniper / junos 12.3x48-d45 12.3x48-d45.x
juniper / junos 15.1-r5 15.1-r5.x
juniper / junos 12.3x48-d55 12.3x48-d55.x
juniper / junos 15.1-r1 15.1-r1.x
juniper / junos 15.1x49-d40 15.1x49-d40.x
juniper / junos 15.1-f2-s1 15.1-f2-s1.x
juniper / junos 15.1-r5-s1 15.1-r5-s1.x
juniper / junos 17.2-r2 17.2-r2.x
juniper / junos 15.1-f5 15.1-f5.x
juniper / junos 12.3x48-d20 12.3x48-d20.x
juniper / junos 16.1-r3 16.1-r3.x
juniper / junos 15.1x49-d20 15.1x49-d20.x
juniper / junos 16.1-r5 16.1-r5.x
juniper / junos 15.1x49-d10 15.1x49-d10.x
juniper / junos 14.1x53-d26 14.1x53-d26.x
juniper / junos 15.1x49-d55 15.1x49-d55.x
juniper / junos 15.1x49-d15 15.1x49-d15.x
juniper / junos 12.3x48-d40 12.3x48-d40.x
juniper / junos 16.1-r2 16.1-r2.x
juniper / junos 14.1x53-d50 14.1x53-d50.x
juniper / junos 15.1-r5-s6 15.1-r5-s6.x
juniper / junos 15.1-r6-s2 15.1-r6-s2.x
juniper / junos 17.2-r1-s2 17.2-r1-s2.x
juniper / junos 15.1x49-d25 15.1x49-d25.x
juniper / junos 12.3x48-d60 12.3x48-d60.x
juniper / junos 12.3x48-d65 12.3x48-d65.x
juniper / junos 14.1x53-d46 14.1x53-d46.x
juniper / junos 15.1x49-d120 15.1x49-d120.x
juniper / junos 15.1x49-d130 15.1x49-d130.x
juniper / junos 15.1-r4-s9 15.1-r4-s9.x
juniper / junos 15.1-r6-s6 15.1-r6-s6.x
juniper / junos 16.1-r5-s4 16.1-r5-s4.x
juniper / junos 16.1-r6-s1 16.1-r6-s1.x
juniper / junos 16.1-r7 16.1-r7.x
juniper / junos 17.3-r2 17.3-r2.x
juniper / junos 17.4-r1 17.4-r1.x
juniper / junos 17.4-r2 17.4-r2.x
juniper / junos 15.1-f 15.1-f.x
juniper / junos 12.3x48-d70 12.3x48-d70.x
juniper / junos 15.1x49-d140 15.1x49-d140.x
juniper / junos 17.3-r2-s2 17.3-r2-s2.x
juniper / junos 15.1-f6-s3 15.1-f6-s3.x
juniper / junos 14.1x53-d47 14.1x53-d47.x
juniper / junos 14.1x53-d48 14.1x53-d48.x
juniper / junos 18.1-r3 18.1-r3.x
juniper / junos 15.1-r7-s1 15.1-r7-s1.x
juniper / junos 17.2-r2-s6 17.2-r2-s6.x
juniper / junos 12.3x48-d75 12.3x48-d75.x
juniper / junos 15.1x49-d160 15.1x49-d160.x
juniper / junos 16.1-r6-s6 16.1-r6-s6.x
juniper / junos 18.1-r2 18.1-r2.x
juniper / junos 16.1-r3-s10 16.1-r3-s10.x
juniper / junos 17.2-r1-s7 17.2-r1-s7.x
juniper / junos 15.1-r7-s2 15.1-r7-s2.x
juniper / junos 15.1-r7-s3 15.1-r7-s3.x
juniper / junos 12.3x48-d51 12.3x48-d51.x
juniper / junos 17.4-r2-s2 17.4-r2-s2.x
juniper / junos 17.2-r1-s1 17.2-r1-s1.x
juniper / junos 17.2-r1-s3 17.2-r1-s3.x
juniper / junos 17.2-r1-s5 17.2-r1-s5.x
juniper / junos 17.4-r1-s1 17.4-r1-s1.x
juniper / junos 12.3x48-d80 12.3x48-d80.x
juniper / junos 15.1x49-d150 15.1x49-d150.x
juniper / junos 18.2 18.2.x
juniper / junos 18.2-r2-s1 18.2-r2-s1.x
juniper / junos 18.2-r2-s2 18.2-r2-s2.x
juniper / junos 18.2-r1-s3 18.2-r1-s3.x
juniper / junos 18.3-r1-s1 18.3-r1-s1.x
juniper / junos 17.2-r1-s4 17.2-r1-s4.x
juniper / junos 17.3-r3-s1 17.3-r3-s1.x
juniper / junos 17.3-r3-s2 17.3-r3-s2.x
juniper / junos 17.4-r1-s2 17.4-r1-s2.x
juniper / junos 17.3-r2-s1 17.3-r2-s1.x
juniper / junos 18.3-r2 18.3-r2.x
juniper / junos 18.3-r1 18.3-r1.x
juniper / junos 17.4-r3 17.4-r3.x
juniper / junos 17.4-r2-s1 17.4-r2-s1.x
juniper / junos 18.1-r2-s2 18.1-r2-s2.x
juniper / junos 15.1-f6-s2 15.1-f6-s2.x
juniper / junos 15.1-f6-s1 15.1-f6-s1.x
juniper / junos 18.4-r1 18.4-r1.x
juniper / junos 17.4 17.4.x
juniper / junos 18.1-r3-s4 18.1-r3-s4.x
juniper / junos 18.1-r3-s3 18.1-r3-s3.x
juniper / junos 18.1-r3-s2 18.1-r3-s2.x
juniper / junos 18.1 18.1.x
juniper / junos 18.1-r2-s1 18.1-r2-s1.x
juniper / junos 18.1-r2-s4 18.1-r2-s4.x
juniper / junos 15.1 15.1.x
juniper / junos 16.1 16.1.x
juniper / junos 17.2 17.2.x
juniper / junos 17.3 17.3.x
juniper / junos 12.3-r12-s8 12.3-r12-s8.x
juniper / junos 12.3x48 12.3x48.x
juniper / junos 14.1x53 14.1x53.x
juniper / junos 15.1x49 15.1x49.x
juniper / junos 18.3-r1-s2 18.3-r1-s2.x
juniper / junos 18.3 18.3.x
juniper / junos 18.4 18.4.x
juniper / junos 17.4-r1-s5 17.4-r1-s5.x
juniper / junos 18.1-r3-s1 18.1-r3-s1.x
juniper / junos 17.3-r3 17.3-r3.x
juniper / junos 17.3-r3-s3 17.3-r3-s3.x
juniper / junos 17.4-r1-s7 17.4-r1-s7.x
juniper / junos 12.3 12.3.x
juniper / junos 16.1-r3-s11 16.1-r3-s11.x
juniper / junos 17.4-r1-s4 17.4-r1-s4.x
juniper / junos 18.4-r1-s1 18.4-r1-s1.x
juniper / junos 15.1x49-d180 15.1x49-d180.x
juniper / junos 15.1x49-d170 15.1x49-d170.x
juniper / junos 17.3-r3-s4 17.3-r3-s4.x
juniper / junos 17.4-r2-s3 17.4-r2-s3.x
juniper / junos 17.4-r2-s4 17.4-r2-s4.x
juniper / junos 17.4-r1-s6 17.4-r1-s6.x
juniper / junos 18.3-r1-s3 18.3-r1-s3.x
juniper / junos 17.2-r2-s7 17.2-r2-s7.x
juniper / junos 18.2-r2-s3 18.2-r2-s3.x
juniper / junos 18.2-r2-s4 18.2-r2-s4.x
juniper / junos 14.1x53-d49 14.1x53-d49.x
juniper / junos 17.2-r3-s1 17.2-r3-s1.x
juniper / junos 18.2-r1-s5 18.2-r1-s5.x
juniper / junos 17.2-r1-s8 17.2-r1-s8.x
juniper / junos 12.3x48-d85 12.3x48-d85.x
juniper / junos 18.4-r1-s3 18.4-r1-s3.x
juniper / junos 18.4-r1-s4 18.4-r1-s4.x
juniper / junos 18.4-r1-s2 18.4-r1-s2.x
juniper / junos 19.1-r1 19.1-r1.x
juniper / junos 19.1 19.1.x
juniper / junos 17.3-r2-s3 17.3-r2-s3.x
juniper / junos 16.1-r7-s3 16.1-r7-s3.x
juniper / junos 16.1-r7-s4 16.1-r7-s4.x
juniper / junos 17.2-r3-s2 17.2-r3-s2.x
juniper / junos 17.4-r2-s5 17.4-r2-s5.x
juniper / junos 17.4-r2-s6 17.4-r2-s6.x
juniper / junos 17.4-r2-s7 17.4-r2-s7.x
juniper / junos 19.2-r1 19.2-r1.x
juniper / junos 18.4-r2 18.4-r2.x
juniper / junos 18.2-r3 18.2-r3.x
juniper / junos 18.1-r3-s6 18.1-r3-s6.x
juniper / junos 18.1-r3-s7 18.1-r3-s7.x
juniper / junos 19.1-r1-s1 19.1-r1-s1.x
juniper / junos 19.1-r1-s3 19.1-r1-s3.x
juniper / junos 19.1-r1-s2 19.1-r1-s2.x
juniper / junos 12.3-r12-s13 12.3-r12-s13.x
juniper / junos 12.3-r12-s14 12.3-r12-s14.x
juniper / junos 15.1-r7-s4 15.1-r7-s4.x
juniper / junos 17.3-r1-s1 17.3-r1-s1.x
juniper / junos 15.1-r7-s5 15.1-r7-s5.x
juniper / junos 16.1-r7-s2 16.1-r7-s2.x
juniper / junos 18.2-r2-s5 18.2-r2-s5.x
juniper / junos 18.2-r2-s6 18.2-r2-s6.x
juniper / junos 18.4-r1-s5 18.4-r1-s5.x
juniper / junos 15.1-f6-s12 15.1-f6-s12.x
juniper / junos 19.2-r1-s1 19.2-r1-s1.x
juniper / junos 19.2-r1-s2 19.2-r1-s2.x
juniper / junos 18.3-r1-s5 18.3-r1-s5.x
juniper / junos 18.2-r3-s1 18.2-r3-s1.x
juniper / junos 15.1x49-d190 15.1x49-d190.x
juniper / junos 16.1-r7-s5 16.1-r7-s5.x
juniper / junos 12.3-r12-s1 12.3-r12-s1.x
juniper / junos 12.3-r12-s3 12.3-r12-s3.x
juniper / junos 12.3-r12-s4 12.3-r12-s4.x
juniper / junos 12.3-r12-s6 12.3-r12-s6.x
juniper / junos 12.3-r12-s11 12.3-r12-s11.x
juniper / junos 12.3-r12-s12 12.3-r12-s12.x
juniper / junos 16.1-r4-s12 16.1-r4-s12.x
juniper / junos 16.1-r4-s6 16.1-r4-s6.x
juniper / junos 16.1-r4-s2 16.1-r4-s2.x
juniper / junos 17.3-r2-s4 17.3-r2-s4.x
juniper / junos 14.1x53-d51 14.1x53-d51.x
juniper / junos 18.3-r2-s1 18.3-r2-s1.x
juniper / junos 18.3-r2-s2 18.3-r2-s2.x
juniper / junos 17.4-r2-s8 17.4-r2-s8.x
juniper / junos 12.3-r10-s1 12.3-r10-s1.x
juniper / junos 12.3-r10-s2 12.3-r10-s2.x
juniper / junos 18.4-r2-s1 18.4-r2-s1.x
juniper / junos 17.2-r2-s11 17.2-r2-s11.x
juniper / junos 19.3 19.3.x
juniper / junos 19.3-r1 19.3-r1.x
juniper / junos 19.2 19.2.x
juniper / junos 18.4-r2-s2 18.4-r2-s2.x
juniper / junos 18.3-r1-s6 18.3-r1-s6.x
juniper / junos 18.2-r3-s2 18.2-r3-s2.x
juniper / junos 18.1-r3-s8 18.1-r3-s8.x
juniper / junos 14.1x53-d52 14.1x53-d52.x
juniper / junos 19.2-r1-s3 19.2-r1-s3.x
juniper / junos 18.3-r3 18.3-r3.x
juniper / junos 16.1-r7-s6 16.1-r7-s6.x
juniper / junos 19.4-r1 19.4-r1.x
juniper / junos 19.3-r2 19.3-r2.x
juniper / junos 18.4-r3 18.4-r3.x
juniper / junos 18.4-r2-s3 18.4-r2-s3.x
juniper / junos 18.3-r3-s1 18.3-r3-s1.x
juniper / junos 18.1-r3-s9 18.1-r3-s9.x
juniper / junos 17.3-r3-s7 17.3-r3-s7.x
juniper / junos 15.1x49-d200 15.1x49-d200.x
juniper / junos 19.3-r2-s1 19.3-r2-s1.x
juniper / junos 19.3-r1-s1 19.3-r1-s1.x
juniper / junos 20.1-r1 20.1-r1.x
juniper / junos 19.4-r1-s1 19.4-r1-s1.x
juniper / junos 19.3-r2-s2 19.3-r2-s2.x
juniper / junos 19.1-r1-s4 19.1-r1-s4.x
juniper / junos 18.4-r1-s6 18.4-r1-s6.x
juniper / junos 18.3-r2-s3 18.3-r2-s3.x
juniper / junos 18.2-r3-s3 18.2-r3-s3.x
juniper / junos 17.4-r3-s1 17.4-r3-s1.x
juniper / junos 17.4-r2-s9 17.4-r2-s9.x
juniper / junos 17.4-r2-s10 17.4-r2-s10.x
juniper / junos 17.2-r3-s3 17.2-r3-s3.x
juniper / junos 16.1-r7-s7 16.1-r7-s7.x
juniper / junos 15.1x49-d210 15.1x49-d210.x
juniper / junos 14.1x53-d53 14.1x53-d53.x
juniper / junos 12.3x48-d95 12.3x48-d95.x
juniper / junos 12.3x48-d90 12.3x48-d90.x
juniper / junos 12.3x48-d100 12.3x48-d100.x
juniper / junos 12.3-r12-s15 12.3-r12-s15.x