CyberzSOC

Publication detail
← Back to advisories & guidance

2024-065: Critical Vulnerability in Juniper Networks Products ↗ source

July 1, 2024 CERT-EU Advisory

Summary

This vulnerability allows an attacker to bypass authentication and gain full control of the device, primarily affecting high-availability redundant configurations [1]. The vulnerability, CVE-2024-2973, is an authentication bypass using an alternate path or channel. It affects Juniper Networks SSR and Conductor running in high-availability configurations, allowing attackers to bypass authentication and take control of the device [1]. – 6.2 versions before 6.2.5-sts CERT-EU recommends updating affected devices to the latest versions as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-2973 10.0 Critical Juniper Networks Session Smart Router An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redund…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.