CVE-2024-21591 is a critical Out-of-bounds Write vulnerability in the J-Web interface of Juniper Networks Junos OS, impacting SRX Series and EX Series devices. This flaw, stemming from an insecure function, allows an unauthenticated, network-based attacker to achieve Denial of Service (DoS) or Remote Code Execution (RCE) with root privileges. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, it has garnered significant community discussion and media coverage, indicating high awareness, though public exploit code (Metasploit, Nuclei, ExploitDB) is not yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 20.4R3-S9CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 21.2, < 21.2R3-S7CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 21.3, < 21.3R3-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 21.4, < 21.4R3-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 22.1, < 22.1R3-S4CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.