#VU94352 Improper neutralization of data within xpath expressions in Juniper Junos OS - CVE-2024-39565
Published: July 15, 2024
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of data within xpath expressions. While an administrator is logged into a J-Web session or has previously logged in and subsequently logged out of their J-Web session, the attacker can arbitrarily execute commands on the target device with the other user's credentials.