{"id":105422,"date":"2022-10-30T21:36:53","date_gmt":"2022-10-30T19:36:53","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos"},"modified":"2022-10-30T21:36:53","modified_gmt":"2022-10-30T19:36:53","slug":"uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","title":{"rendered":"Vulnerabilit\u00e0 nell'interfaccia web dei dispositivi di rete Juniper forniti con JunOS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel web interface J-Web, utilizzato nei dispositivi di rete dell'azienda Juniper dotati del sistema operativo JunOS, sono state rilevate diverse vulnerabilit\u00e0, la pi\u00f9 pericolosa delle quali (CVE-2022-22241) consente l'esecuzione remota di codice non autenticato nel sistema tramite l'invio di una richiesta HTTP appositamente formattata. Si raccomanda agli utenti dell'hardware Juniper di installare l'aggiornamento del firmware e, se ci\u00f2 non \u00e8 possibile, di garantire che l'accesso al web interface sia bloccato dalle reti esterne e limitato solo a host fidati.      <\/p>\n<p>La vulnerabilit\u00e0 risiede nel fatto che il percorso del file fornito dall'utente viene elaborato nello script \/jsdm\/ajax\/logging_browse.php senza filtrare il prefisso con il tipo di contenuto in fase di autenticazione. Un attaccante pu\u00f2 inviare un file phar malevolo spacciandolo per immagine e ottenere l'esecuzione di codice PHP incorporato nell'archivio phar, sfruttando il metodo d'attacco 'Phar deserialization' (ad esempio, specificando nella richiesta 'filepath=phar:\/percorso\/pharfile.jpg').     <\/p>\n<p>Il problema \u00e8 che durante il controllo del file caricato tramite la funzione PHP is_dir(), questa funzione esegue automaticamente la deserializzazione dei metadati dall'archivio Phar (PHP Archive) quando elabora percorsi che iniziano con 'phar:\/\/'. Un effetto simile si osserva nel trattamento dei percorsi di file forniti dall'utente nelle funzioni file_get_contents(), fopen(), file(), file_exists(), md5_file(), filemtime() e filesize().     <\/p>\n<p>L'attacco \u00e8 complicato dal fatto che, oltre a innescare l'esecuzione dell'archivio phar, l'aggressore deve trovare un modo per caricarlo sul dispositivo (attraverso accessi a \/jsdm\/ajax\/logging_browse.php si pu\u00f2 solo specificare un percorso per eseguire un file gi\u00e0 esistente). Tra gli scenari possibili per il caricamento dei file sul dispositivo sono menzionati il caricamento di un file phar spacciato per un'immagine tramite un servizio di trasferimento delle immagini e l'inserimento di un file nella cache dei contenuti web.    <\/p>\n<p>Altre vulnerabilit\u00e0:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-22242 \u2014 l'inserimento di parametri esterni non filtrati nell'output dello script error.php consente di ottenere cross-site scripting e di eseguire codice JavaScript arbitrario nel browser dell'utente accedendo a un link (ad esempio, 'https:\/\/JUNOS_IP\/error.php?SERVER_NAME='). La vulnerabilit\u00e0 pu\u00f2 essere sfruttata per intercettare i parametri di sessione dell'amministratore, se l'attaccante riesce a far aprire un link appositamente preparato dall'amministratore.\n<li class=\"l\"> CVE-2022-22243, CVE-2022-22244 \u2014 l'inserimento di espressioni XPATH tramite gli script jsdm\/ajax\/wizards\/setup\/setup.php e \/modules\/monitor\/interfaces\/interface.php consente a un utente autenticato non privilegiato di manipolare le sessioni dell'amministratore.\n<li class=\"l\"> CVE-2022-22245 \u2014 l'assenza di una corretta pulizia delle sequenze '..' nei percorsi elaborati nello script Upload.php consente a un utente autenticato di caricare il proprio file PHP in una cartella che consente l'esecuzione di script PHP (ad esempio, inviando il percorso 'fileName=..\\..\\..\\..\\www\\dir\\new\\shell.php').\n<li class=\"l\"> CVE-2022-22246 \u2014 la possibilit\u00e0 di eseguire file PHP locali arbitrari attraverso manipolazioni da parte di un utente autenticato con lo script jrest.php, in cui i parametri esterni vengono utilizzati per formare il nome del file caricato dalla funzione 'require_once()' (ad esempio, '\/jrest.php?payload=alol\/lol\/any\\..\\..\\..\\..\\any\\file').      <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58010\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f Juniper \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043d\u043e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438, \u0430 \u0435\u0441\u043b\u0438 \u044d\u0442\u043e \u043d\u0435\u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u043f\u0440\u043e\u0441\u043b\u0435\u0434\u0438\u0442\u044c, \u0447\u0442\u043e\u0431\u044b \u0434\u043e\u0441\u0442\u0443\u043f \u043a web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0443 \u0431\u044b\u043b \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-105422","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 Juniper, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0441 JunOS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-10-30T19:36:53+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-10-30T19:36:53+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 nell'interfaccia web dei dispositivi di rete Juniper forniti con JunOS | ProHoster","description":"Nel web interface J-Web, utilizzato nei dispositivi di rete dell'azienda Juniper dotati del sistema operativo JunOS, sono state identificate diverse vulnerabilit\u00e0, la pi\u00f9 pericolosa delle quali (CVE-2022-22241) consente.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 Juniper, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0441 JunOS | ProHoster","og:description":"\u0412 web-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 J-Web, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Juniper, \u043e\u0441\u043d\u0430\u0449\u0451\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 JunOS, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 (CVE-2022-22241) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-web-interfejse-setevyh-ustrojstv-juniper-postavlyaemyh-s-junos","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-10-30T19:36:53+00:00","article:modified_time":"2022-10-30T19:36:53+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/105422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=105422"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/105422\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=105422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=105422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=105422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}