CVE-2024-2973 is a critical authentication bypass vulnerability affecting Juniper Networks Session Smart Routers and Conductors configured for high-availability redundancy. An unauthenticated network-based attacker can exploit this flaw to gain full control of the device. This vulnerability carries a CVSS score of 10.0 (Critical) due to its network attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While there is no public exploit code or Metasploit module, the vulnerability is listed on the Hot List, indicating active monitoring, and has garnered significant community discussion and media coverage, including an out-of-cycle fix release by Juniper.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Juniper Networks | Session Smart Conductor | >= 0, < 5.6.15, >= 6.0, < 6.1.9-lts, >= 6.2, < 6.2.5-stsCNA affecteddefault unaffected | |
| Juniper Networks | Session Smart Router | >= 0, < 5.6.15, >= 6.0, < 6.1.9-lts, >= 6.2, < 6.2.5-stsCNA affecteddefault unaffected | |
| Juniper Networks | WAN Assurance Router | >= 6.0, < 6.1.9-lts, >= 6.2, < 6.2.5-stsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.