Vulnerabilities in the web interface of Juniper network devices shipped with JunOS

Several vulnerabilities have been identified in the J-Web web interface used in network devices from Juniper that run the JunOS operating system. The most critical of these (CVE-2022-22241) allows for remote code execution without authentication through the submission of a specially crafted HTTP request. Users of Juniper equipment are advised to install a firmware update. If this is not possible, they should ensure that access to the web interface is blocked from external networks and limited to trusted hosts.

The essence of the vulnerability lies in the fact that the user-supplied file path is processed in the script /jsdm/ajax/logging_browse.php without filtering the prefix regarding content type before authentication verification. An attacker can pass a malicious phar file disguised as an image, executing the PHP code placed in the phar archive by leveraging the "Phar deserialization" attack method (e.g., specifying in the request "filepath=phar:/path/pharfile.jpg").

The problem is that when checking the uploaded file using the PHP function is_dir(), this function automatically performs metadata deserialization from the Phar archive (PHP Archive) when processing paths starting with "phar://". A similar effect is observed while processing user-supplied file paths in the functions file_get_contents(), fopen(), file(), file_exists(), md5_file(), filemtime(), and filesize().

The attack is complicated by the fact that, in addition to initiating the execution of the phar archive, the attacker must find a way to upload it to the device (accessing /jsdm/ajax/logging_browse.php only allows specifying a path for executing an already existing file). Possible scenarios for uploading files to the device include uploading a phar file disguised as an image via an image transfer service and placing a file in the web content cache.

Other vulnerabilities:

  • CVE-2022-22242 — the insertion of unfiltered external parameters into the output of the error.php script allows for cross-site scripting (XSS), enabling arbitrary JavaScript code execution in the user's browser when navigating to a link (e.g., "https://JUNOS_IP/error.php?SERVER_NAME="). The vulnerability could be exploited to capture administrative session parameters if the attacker successfully gets the administrator to open a specially crafted link.
  • CVE-2022-22243, CVE-2022-22244 — XPATH expression injection through scripts jsdm/ajax/wizards/setup/setup.php and /modules/monitor/interfaces/interface.php allows an unauthenticated user to manipulate admin sessions.
  • CVE-2022-22245 — insufficient cleaning of the ".." sequence in paths processed in the Upload.php script allows an authenticated user to upload their PHP file to a directory that permits PHP script execution (for example, by passing the path "fileName=\..\..\..\..\www\dir\new\shell.php").
  • CVE-2022-22246 — the possibility of executing arbitrary local PHP files through manipulation by an authenticated user with the jrest.php script, where external parameters are used to form the filename loaded by the "require_once()" function (for example, "/jrest.php?payload=alol/lol/any\..\..\..\..\any\file").

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster