Juniper releases out-of-cycle fix for max severity auth bypass flaw

To fix a maximum severity vulnerability that allows authentication bypass in the Session Smart Router (SSR), Session Smart Conductor, and WAN Assurance Router devices, Juniper Networks has published an emergency update.

An attacker may be able to use the security flaw, which is listed as CVE-2024-2973, to gain complete control of the device.

A Workaround for Authentication A network-based attacker can get beyond authentication and gain complete control of a Juniper Networks Session Smart Router or Conductor operating with a redundant peer by using an Alternate Path or Channel vulnerability, according to the vulnerability description.

This issue affects only Routers or Conductors operating in high-availability redundant setups read more about Juniper releases out-of-cycle fix for max severity auth bypass flaw.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *