{"id":105422,"date":"2022-10-30T21:36:53","date_gmt":"2022-10-30T19:36:53","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos"},"modified":"2022-10-30T21:36:53","modified_gmt":"2022-10-30T19:36:53","slug":"uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","title":{"rendered":"Vulnerabilidades en la interfaz web de los dispositivos de red Juniper que se env\u00edan con JunOS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se han identificado varias vulnerabilidades en la interfaz web J-Web, que se utiliza en los dispositivos de red de Juniper equipados con el sistema operativo JunOS. La m\u00e1s cr\u00edtica (CVE-2022-22241) permite ejecutar c\u00f3digo de forma remota sin autenticaci\u00f3n mediante el env\u00edo de una solicitud HTTP especialmente formada. Se recomienda a los usuarios del equipo Juniper que instalen una actualizaci\u00f3n de firmware, y si esto no es posible, que se aseguren de que el acceso a la interfaz web est\u00e9 bloqueado desde redes externas y que est\u00e9 limitado a hosts de confianza.      <\/p>\n<p>La vulnerabilidad reside en que la ruta de archivo proporcionada por el usuario se procesa en el script \/jsdm\/ajax\/logging_browse.php sin filtrar el prefijo del tipo de contenido antes de la verificaci\u00f3n de autenticaci\u00f3n. Un atacante puede enviar un archivo phar malicioso haci\u00e9ndose pasar por una imagen y lograr que se ejecute c\u00f3digo PHP contenido en el archivo phar aprovechando el m\u00e9todo de ataque 'Deserializaci\u00f3n de Phar' (por ejemplo, especificando en la solicitud 'filepath=phar:\/ruta\/pharfile.jpg').     <\/p>\n<p>El problema es que al verificar el archivo cargado mediante la funci\u00f3n PHP is_dir(), esta funci\u00f3n deserializa autom\u00e1ticamente los metadatos del archivo Phar (PHP Archive) al procesar rutas que comienzan con 'phar:\/\/'. Un efecto similar se observa al procesar las rutas de archivo proporcionadas por el usuario en las funciones file_get_contents(), fopen(), file(), file_exists(), md5_file(), filemtime() y filesize().     <\/p>\n<p>El ataque se complica porque, adem\u00e1s de iniciar la ejecuci\u00f3n del archivo phar, el atacante debe encontrar una forma de cargarlo en el dispositivo (a trav\u00e9s de \/jsdm\/ajax\/logging_browse.php s\u00f3lo se puede especificar una ruta para ejecutar un archivo ya existente). Se mencionan entre los posibles escenarios de carga de archivos en el dispositivo el env\u00edo de un archivo phar haci\u00e9ndose pasar por una imagen a trav\u00e9s de un servicio de transferencia de im\u00e1genes y la inserci\u00f3n del archivo en la cach\u00e9 del contenido web.    <\/p>\n<p>Otras vulnerabilidades:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-22242 \u2014 la inserci\u00f3n de par\u00e1metros externos no filtrados en la salida del script error.php permite la ejecuci\u00f3n de scripts entre sitios y ejecutar c\u00f3digo JavaScript arbitrario en el navegador del usuario al seguir un enlace (por ejemplo, 'https:\/\/JUNOS_IP\/error.php?SERVER_NAME='). La vulnerabilidad puede ser utilizada para interceptar los par\u00e1metros de sesi\u00f3n del administrador si el atacante logra hacer que el administrador abra un enlace especialmente dise\u00f1ado.\n<li class=\"l\"> CVE-2022-22243, CVE-2022-22244 \u2014 la inserci\u00f3n de expresiones XPATH a trav\u00e9s de los scripts jsdm\/ajax\/wizards\/setup\/setup.php y \/modules\/monitor\/interfaces\/interface.php permite a un usuario autenticado no privilegiado manipular las sesiones del administrador.\n<li class=\"l\"> CVE-2022-22245 \u2014 la falta de limpieza adecuada de la secuencia '..' en las rutas procesadas en el script Upload.php permite a un usuario autenticado cargar su archivo PHP en un directorio que permite la ejecuci\u00f3n de scripts PHP (por ejemplo, pasando la ruta 'fileName=\touch ..\/www\/dir\/new\/shell.php').\n<li class=\"l\"> CVE-2022-22246 \u2014 la posibilidad de ejecutar un archivo PHP local arbitrario a trav\u00e9s de manipulaciones de un usuario autenticado con el script jrest.php, en el cual se utilizan par\u00e1metros externos para formar el nombre del archivo que se carga mediante la funci\u00f3n 'require_once()' (por ejemplo, '\/jrest.php?payload=alol\/lol\/any..\/....\/anyfile').      <\/ul>\n<p>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58010\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f Juniper \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043d\u043e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438, \u0430 \u0435\u0441\u043b\u0438 \u044d\u0442\u043e \u043d\u0435\u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u043f\u0440\u043e\u0441\u043b\u0435\u0434\u0438\u0442\u044c, \u0447\u0442\u043e\u0431\u044b \u0434\u043e\u0441\u0442\u0443\u043f \u043a web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0443 \u0431\u044b\u043b \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-105422","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 Juniper, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0441 JunOS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-10-30T19:36:53+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-10-30T19:36:53+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidades en la interfaz web de dispositivos de red Juniper suministrados con JunOS | ProHoster","description":"En la interfaz web J-Web, utilizada en dispositivos de red de la compa\u00f1\u00eda Juniper equipados con el sistema operativo JunOS, se han identificado varias vulnerabilidades, siendo la m\u00e1s grave (CVE-2022-22241) la que permite.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 Juniper, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0441 JunOS | ProHoster","og:description":"\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-10-30T19:36:53+00:00","article:modified_time":"2022-10-30T19:36:53+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/105422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=105422"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/105422\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=105422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=105422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=105422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}