Juniper Rushes Out Emergency Patch for Critical Smart Router Flaw

Share This Post

Juniper Networks has released an emergency patch for a critical authentication bypass vulnerability that has been assigned the highest possible CVSS score of 10.

The vulnerability, tracked under CVE-2024-2973, affects the Juniper Networks Session Smart Router, Session Smart Conductor, and WAN Assurance Router, and could allow a threat actor to take full control of an unpatched device.

“Only Routers or Conductors that are running in high-availability redundant configurations are affected by this vulnerability,” the emergency security advisory said.

The router flaw was found during internal security testing, and Juniper Networks added there is no evidence the bug has yet been exploited in the wild. The company recommended immediate updates to Session Smart Routers SSR-5.6.15, SSR-6.1.9-lts, SSR-6.2.5-sts, and subsequent releases. 

“In a Conductor-managed deployment, it is sufficient to upgrade the Conductor nodes only and the fix will be applied automatically to all connected routers,” Juniper’s advisory added. “As practical, the routers should still be upgraded to a fixed version however they will not be vulnerable once they connect to an upgraded Conductor.”

Managed routers will be automatically updated, which won’t impact any data plane router functions, Juniper assured its customers.

“The application of the fix is non-disruptive to production traffic,” Juniper said. “There may be a momentary downtime (less than 30 seconds) to the web-based management and APIs however this will resolve quickly.”

https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blteed444452887dbb5/6682eeba3a6e64fd2d57c20f/Juniper_Networks_crop_John_Crowe_Alamy.jpg?disable=upscale&width=1200&height=630&fit=crop

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.