Security

Patches

Juniper Networks flings out emergency patches for perfect 10 router vuln

Get 'em while they're hot


A critical vulnerability affecting Juniper Networks routers forced the vendor to issue emergency patches last week, and users are advised to apply them as soon as possible.

The authentication bypass bug, tracked as CVE-2024-2973, scored a perfect 10 rating on both the CVSS 3.1 and CVSS 4 systems, illustrating the seriousness of the issue.

"An authentication bypass using an alternate path or channel vulnerability in Juniper Networks Session Smart Router or Conductor running with a redundant peer allows a network-based attacker to bypass authentication and take full control of the device," Juniper said in its advisory.

The bug impacts Juniper's Smart Session Router, Session Smart Conductor management platform, and WAN Assurance Routers and only those that run high-availability redundant configurations are vulnerable.

While there is no evidence to suggest that the vulnerability has been exploited in the wild yet, the fact Juniper released the patches outside of the products' usual cycle hints at the vendor's concern about its severity and exploitability.

With CVE-2024-2973 affecting devices running high-availability configs too, successful attacks have the potential to cause significant disruption.

As for the specific vulnerable versions, for Session Smart Routers it's:

For Session Smart Conductor

And for WAN Assurance Routers

For routers managed by the Session Smart Conductor platform, Juniper said as long as the Conductor nodes are upgraded then the security fixes will automatically apply to connected routers.

The vendor still recommends upgrading each vulnerable router individually, but it would be quicker to protect against CVE-2024-2973 by just upgrading the Conductor nodes before doing the full job.

WAN Assurance Routers would also have had the patch applied automatically already if they were managed by and connected to Juniper Mist, its AI-driven cloud platform.

"It is important to note that the fix is applied automatically on managed routers by a Conductor or on WAN Assurance Routers has no impact on data-plane functions of the router. The application of the fix is non-disruptive to production traffic," Juniper said. 

"There may be a momentary downtime (less than 30 seconds) to the web-based management and APIs however this will resolve quickly." ®

Send us news
6 Comments

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

Infosec hounds say they spotted vulnerability during routine travel in the US

Check your IP cameras: There's a new Mirai botnet on the rise

Also, US offering $2.5M for Belarusian hacker, Backpage kingpins jailed, additional MOVEit victims, and more

US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

Rap sheet spells out major no-nos after disgruntled staff blow whistle

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

French police reckon financial system targeted during Summer Games

Multiple flaws in Microsoft macOS apps unpatched despite potential risks

Windows giant tells Cisco Talos it isn't fixing them

Deadline looms: Google Workspace mandates OAuth by September 30

27 days to get your users' third-party apps on Google’s sign-in

RansomHub hits 210 victims in just 6 months

The ransomware gang recruits high-profile affiliates from LockBit and ALPHV

AMD reverses course: Ryzen 3000 CPUs will get SinkClose patch after all

Still no love for 1000- or 2000-series

RansomHub-linked EDR-killing malware spotted in the wild

Also: Your external-facing NetSuite sites need a review; five popular malware varieties for Q2, and more

Ransomware batters critical industries, but takedowns hint at relief

Whether attack slowdown continues downward trend is the million dollar question that security researchers can't answer

110K domains targeted in 'sophisticated' AWS cloud extortion campaign

If you needed yet another reminder of what happens when security basics go awry

Russia tells citizens to switch off home surveillance because the Ukrainians are coming

Forget about your love life too, no dating apps until the war is over