EXPOSURES › CVE-2020-1631
CVE-2020-1631
HIGH ⌖ ON CISA KEV · EXPLOITEDJuniper Junos OS path traversal flaw in J-Web and related services allows unauthenticated remote code execution.
An unauthenticated attacker can exploit this path traversal vulnerability in Juniper Junos OS to execute arbitrary code remotely via J-Web, Web Authentication, DVPN, and ZTP services. This is a critical failure for DIB organizations relying on Juniper networking gear, as it directly enables remote code execution without authentication, violating core security controls and risking network compromise. Organizations must immediately patch Junos OS and restrict access to these web services until a fix is applied.
Shame score — A path traversal flaw enabling unauthenticated remote code execution in core networking OS is a severe, avoidable failure that directly compromises network integrity and violates fundamental security principles.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
| PRODUCT | STATUS |
|---|---|
| Juniper Mist Juniper Networks |
In Process |