Authentication bypass using an alternate path or channel in Juniper Networks, Inc. products - CVE-2024-2973
Published: July 1, 2024
Vulnerability identifier: #VU93506
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2973
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected device.
The vulnerability exists due to missing authentication checks when running with a redundant peer. A remote non-authenticated attacker can bypass authentication and take full control over the affected device.
Affected software
Session Smart Router
Session Smart Conductor
WAN Assurance Router
Session Smart Conductor
WAN Assurance Router
How to mitigate CVE-2024-2973
Install updates from vendor's website.
Session Smart Router - addressed in versions 5.6.15, 6.1.9, 6.2.5
Session Smart Conductor - addressed in versions 5.6.15, 6.1.9, 6.2.5
WAN Assurance Router - addressed in versions 6.1.9, 6.2.5
Session Smart Conductor - addressed in versions 5.6.15, 6.1.9, 6.2.5
WAN Assurance Router - addressed in versions 6.1.9, 6.2.5