CVE-2021-31349
Session Smart Router: Authentication Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1.
El uso de un encabezado HTTP interno creó una vulnerabilidad de omisión de autenticación (CWE-287), que permite a un atacante visualizar archivos internos, cambiar la configuración, manipular servicios y ejecutar código arbitrario. Este problema afecta a todas las versiones de Juniper Networks 128 Technology Session Smart Router anteriores a 4.5.11 y a todas las versiones de la 5.0 hasta la 5.0.1 incluyéndola
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-15 CVE Reserved
- 2021-10-19 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Juniper Search vendor "Juniper" | 128 Technology Session Smart Router Firmware Search vendor "Juniper" for product "128 Technology Session Smart Router Firmware" | < 4.5.11 Search vendor "Juniper" for product "128 Technology Session Smart Router Firmware" and version " < 4.5.11" | - |
Affected
| in | Juniper Search vendor "Juniper" | 128 Technology Session Smart Router Search vendor "Juniper" for product "128 Technology Session Smart Router" | - | - |
Safe
|
Juniper Search vendor "Juniper" | 128 Technology Session Smart Router Firmware Search vendor "Juniper" for product "128 Technology Session Smart Router Firmware" | >= 5.0.0 <= 5.0.1 Search vendor "Juniper" for product "128 Technology Session Smart Router Firmware" and version " >= 5.0.0 <= 5.0.1" | - |
Affected
| in | Juniper Search vendor "Juniper" | 128 Technology Session Smart Router Search vendor "Juniper" for product "128 Technology Session Smart Router" | - | - |
Safe
|