CVE-2024-39563

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 77

Summary

CVE-2024-39563 is a critical Command Injection vulnerability affecting Juniper Networks Junos Space. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted network request to the Junos Space Appliance, leading to remote command execution. The vulnerability exists in a specific script in the Junos Space web application, which allows for attacker-controlled input in a GET request without proper input sanitization. This issue puts the Junos Space Appliance at risk of complete control by an attacker. Junos Space 24.1R1 is affected by this vulnerability, while earlier versions are not.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Junos Space

Affected Vendors

  • Juniper Networks